You have a Microsoft 365 E5 subscription.
You have a Microsoft Intune enrollment profile for Android Enterprise devices that has the following settings:
• Name: Profile1
• Token type: Corporate-owned, fully managed
You need to enroll a new Android device in Intune by using Profile1.
What should you use to enroll the device?
A. a QR code
B. the Company Portal app
C. the Microsoft Authenticator app
D. the Intune app
Show Answer
Correct Answer: A
Explanation: For Android Enterprise devices enrolled as Corporate-owned, fully managed, Intune uses the Android Enterprise QR code enrollment method. During the device’s out-of-box setup after a factory reset, scanning the QR code from the Intune enrollment profile provisions the device and enrolls it into Intune. Apps like Company Portal or Authenticator are not used for this enrollment type.
Question 44
You have a Microsoft 365 E5 subscription and use Microsoft Intune Suite.
You plan to use Intune to run remediation script packages.
What should you do first in the Microsoft Intune admin center?
A. Enable Windows diagnostic data in processor configuration.
B. Enable Windows license verification.
C. Configure the Derived Credential settings.
D. Upload a Windows enterprise certificate.
Show Answer
Correct Answer: B
Explanation: To use Intune remediation (Proactive Remediations) script packages, the tenant must first confirm it owns the required Windows Enterprise/Education licensing. In the Intune admin center, this is done by enabling Windows license verification (toggling the confirmation that the tenant owns an eligible license). This step is required before creating or running remediation script packages; the other options are unrelated prerequisites.
Question 45
You have a Microsoft 365 E5 subscription and use Microsoft Intune.
You need to use a Sync bulk device action on all corporate-owned Windows devices.
What is the maximum number of devices you can include the action?
A. 25
B. 50
C. 100
D. 500
E. 1000
Show Answer
Correct Answer: C
Explanation: In Microsoft Intune, bulk device actions generally have a maximum selection limit of 100 devices. According to Microsoft Learn documentation, most bulk actions—including Sync—support up to 100 devices at a time. This aligns with long‑standing Intune behavior and current exam (MD‑102) expectations, even though some newer experiences or specific actions may allow higher limits.
Question 46
HOTSPOT
-
You manage devices by using Microsoft Intune. Automatic Intune enrollment is disabled.
Users report that they must enter the mobile device management (MDM) server address during device enrollment.
To reduce user interaction during device enrollment, you plan to create the following CNAME DNS hostname records:
• EnterpriseEnrollment.contoso.com
• EnterpriseRegistration.contoso.com
You need to configure a fully qualified domain name (FQDN) for each CNAME record to redirect enrollment requests to the Intune servers.
How should you configure each FQDN? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Explanation: Intune uses DNS-based auto-discovery for MDM enrollment. The EnterpriseEnrollment CNAME must point to the Intune enrollment service (manage.microsoft.com), while the EnterpriseRegistration CNAME must point to Azure AD device registration (windows.net) to avoid users manually entering the MDM server address.
Question 47
HOTSPOT
-
You have a Microsoft 365 subscription that contains 5,000 Windows devices enrolled in Microsoft Intune.
You plan to use the Sync and Collect diagnostics bulk device actions.
What is the maximum number of devices you can include in each action? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Sync: 100
Collect diagnostics: 25
Explanation: In Intune bulk device actions, Sync supports up to 100 devices per action, while Collect diagnostics is limited to 25 Windows devices per action due to the higher impact of data collection.
Question 48
You have a Microsoft 365 E5 subscription that contains the following types of devices:
• Windows 11
• Android
• iOS
All the devices are enrolled in Microsoft Intune.
You need to use Intune to deploy apps from the Enterprise App Catalog.
To which device types can you deploy the apps?
A. Windows 11 only
B. Windows 11 and Android only
C. Windows 11 and is only
D. Android and iOS only
E. Windows 11, Android, and iOS
Show Answer
Correct Answer: A
Explanation: The Intune Enterprise App Catalog (Enterprise App Management) provides prepackaged Win32 applications that are supported only on managed Windows devices. It does not support Android or iOS app deployment, which use Managed Google Play and Apple App Store/VPP respectively. Therefore, apps from the Enterprise App Catalog can be deployed to Windows 11 devices only.
Question 49
HOTSPOT
-
You have a Microsoft 365 subscription and use Microsoft Intune.
You have the Endpoint Privilege Management (EPM) elevation settings policy shown in the following exhibit.
No EPM elevation rules policies are configured.
Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Be denied.
Only diagnostic data.
Explanation: With Default elevation response set to Not configured and no EPM elevation rules, the client falls back to its built-in default behavior, which denies all elevation requests. The reporting scope is set to "Diagnostic data and managed elevations only"; since no elevation rules exist, there are no managed elevations to report, so only diagnostic data is sent.
Question 50
You have a Microsoft 365 subscription and use Microsoft Intune Suite.
You plan to use Microsoft Cloud PKI to support the signing and encryption of email messages.
What should you do first?
A. Create a root certification authority (CA).
B. Create a device compliance policy.
C. Create device configuration SCEP certificate profiles.
D. Create device configuration trusted certificate profiles.
E. Create an issuing certification authority (CA).
Show Answer
Correct Answer: A
Explanation: To use Microsoft Cloud PKI for signing and encrypting email, you must first establish the certificate authority hierarchy. The initial step is creating a root certification authority (CA), which serves as the trust anchor. Only after the root CA exists can you create an issuing CA and then deploy trusted certificate and SCEP profiles to devices.
Question 51
HOTSPOT
-
You have a Microsoft 365 E5 subscription that contains a Windows device named Device1.
Device1 was onboarded to Microsoft Defender for Endpoint by using a local script.
You use Microsoft Intune to manage Device1.
You plan to use the machine risk score in a compliance policy.
You need to ensure that the machine risk score is evaluated based on data from Defender for Endpoint.
What should you do? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: From the Endpoints settings of the Microsoft Defender portal:
Configure the Advanced features settings.
From the Microsoft Intune admin center:
Configure the Microsoft Defender for Endpoint settings.
Explanation: The machine risk score used by Intune compliance policies comes from Microsoft Defender for Endpoint. You must first enable the Microsoft Intune connection in Defender for Endpoint under Advanced features. Then, in the Intune admin center, you enable and configure the Microsoft Defender for Endpoint connector so Intune can consume Defender risk data for compliance evaluation.
Question 52
You have a Microsoft 365 E5 subscription that contains devices enrolled in Microsoft intune.
You need to review security tasks in the Microsoft Intune admin center.
What should you do first?
A. Integrate Intune with Microsoft Defender for Endpoint.
B. Implement the ServiceNow connector.
C. Implement the Mobile Threat Defense connector.
D. Deploy an attack surface reduction (ASR) policy.
E. Deploy an Intune security baseline for Microsoft Defender for Endpoint.
Show Answer
Correct Answer: A
Explanation: Security tasks in the Intune admin center are sourced from Microsoft Defender for Endpoint. To be able to review these tasks, Intune must first be integrated with Defender for Endpoint. Other options (baselines, ASR, connectors) configure security but do not enable the security tasks view itself.
$19
Get all 373 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.