View Full Microsoft MD-102 Exam Dumps and Practice Test Dumps.
Question 101
Which Intune enrollment method is designed for corporate-owned Windows devices that are provisioned through Windows Autopilot?
- Windows Autopilot enrollment
- Device Enrollment Manager
- Microsoft Entra registered enrollment
- Bulk enrollment
Correct Answer: 1
Explanation
Windows Autopilot enrollment is designed to simplify provisioning of corporate-owned Windows devices. Devices can be registered with Autopilot before deployment, allowing organizational policies, applications, and configurations to be applied during the out-of-box experience. Users can receive devices directly from a manufacturer or supplier and complete organizational setup with minimal IT intervention. Device Enrollment Manager is intended for specific enrollment scenarios involving multiple devices, while Microsoft Entra registered devices are commonly associated with personal-device scenarios. Bulk enrollment serves other enrollment requirements and does not provide the standard Autopilot experience.
Question 102
Which Windows Autopilot deployment mode allows a device to be deployed without requiring the user to enter credentials during the initial setup?
- User-driven mode
- Self-deploying mode
- Pre-provisioning
- Autopilot Reset
Correct Answer: 2
Explanation
Windows Autopilot self-deploying mode is designed for scenarios where minimal user interaction is required during device deployment. The device can automatically join Microsoft Entra ID and enroll in Intune while applying organizational policies and applications. This mode is particularly useful for shared devices, kiosks, or other scenarios where a specific user does not need to complete the initial setup. User-driven mode requires the user to authenticate, while pre-provisioning allows technicians to prepare devices before delivery. Autopilot Reset is used to reset an already deployed device for reuse.
Question 103
Which Intune feature allows an administrator to view the compliance status of multiple managed devices from a centralized dashboard?
- Device compliance reporting
- App configuration
- Enrollment restrictions
- Scope tags
Correct Answer: 1
Explanation
Intune compliance reporting provides centralized information about whether managed devices meet configured compliance requirements. Administrators can review device compliance states and identify devices that are compliant, noncompliant, or require attention. This information can also be used with Conditional Access to help control access to organizational resources. App configuration policies manage application settings, enrollment restrictions control which devices can enroll, and scope tags control administrative visibility. Compliance reporting therefore provides the centralized monitoring capability required to review device security and compliance status across an organization.
Question 104
An organization wants to prevent users from copying corporate information from a managed application into personal applications. Which Intune capability should be used?
- Device compliance policy
- Windows Update ring
- App protection policy
- Device cleanup rule
Correct Answer: 3
Explanation
Intune app protection policies can help protect organizational data within supported applications by controlling actions such as copy and paste, saving data to personal locations, and transferring information between applications. This is particularly useful for mobile and BYOD scenarios where organizations want to protect corporate information without necessarily managing the entire device. Compliance policies evaluate device requirements, update rings manage Windows Update behavior, and cleanup rules manage stale device records. App protection policies are therefore appropriate when the primary requirement is controlling how corporate data moves between applications.
Question 105
Which Intune capability allows an organization to assign different Windows configuration policies to devices based on their organizational purpose?
- Device categories
- Remote Help
- Endpoint analytics
- Windows Sandbox
Correct Answer: 1
Explanation
Device categories allow organizations to classify managed devices according to organizational purposes, such as departments, usage types, or other administrative classifications. Categories can help users select an appropriate category during supported enrollment processes and can be used to improve device organization and targeting. Remote Help is intended for remote assistance, Endpoint analytics provides performance insights, and Windows Sandbox provides an isolated testing environment. Device categories are therefore useful when an organization needs a structured way to classify devices and use those classifications for management and assignment purposes.
Question 106
Which Intune capability allows an administrator to remotely assist a user by viewing and controlling a supported managed device?
- Windows Autopilot
- Windows LAPS
- Remote Help
- Storage Sense
Correct Answer: 3
Explanation
Remote Help is an Intune-supported capability that allows authorized help desk personnel to remotely assist users on supported devices. Depending on the session permissions and configuration, the helper can view the user’s screen and interact with the device to troubleshoot problems. This can reduce the need for users to bring devices to an IT department or follow complicated troubleshooting instructions. Windows Autopilot handles device provisioning, Windows LAPS manages local administrator passwords, and Storage Sense manages disk space. Remote Help is specifically intended for remote troubleshooting and user assistance.
Question 107
Which Intune feature allows an administrator to target applications or policies using specific device properties without changing the membership of the assigned group?
- Assignment filters
- Security baselines
- Compliance actions
- Enrollment restrictions
Correct Answer: 1
Explanation
Assignment filters allow Intune administrators to refine application and policy targeting based on device properties. An administrator can assign a policy to a group and then use a filter to include or exclude devices that meet particular criteria. This provides more precise targeting without requiring the administrator to create numerous separate groups. Security baselines configure security settings, compliance actions define responses to noncompliant devices, and enrollment restrictions determine which devices are allowed to enroll. Assignment filters are therefore useful for flexible and granular targeting of managed devices.
Question 108
A company uses Microsoft Entra ID and on-premises Active Directory and wants Windows devices to work with both environments. Which device identity should be used?
- Microsoft Entra registered
- Microsoft Entra joined
- Hybrid Microsoft Entra joined
- Workgroup
Correct Answer: 3
Explanation
Hybrid Microsoft Entra joined devices are connected to both an on-premises Active Directory environment and Microsoft Entra ID. This configuration is commonly used by organizations that still depend on traditional domain services while also adopting cloud-based identity and management capabilities. It allows Windows devices to maintain their domain relationship while obtaining a Microsoft Entra device identity. Microsoft Entra joined devices are cloud-focused and do not require a traditional domain relationship. Registered devices are commonly used for personal-device scenarios, while workgroup devices are not joined to either organizational directory.
Question 109
Which Intune application deployment type is commonly used to deploy traditional Windows desktop applications with custom installation commands?
- Microsoft Store app
- Win32 app
- Web app
- Built-in application
Correct Answer: 2
Explanation
Win32 app deployment in Intune is designed for traditional Windows desktop applications that can be packaged and deployed using installation commands and detection rules. Administrators can specify install and uninstall commands, requirements, detection rules, dependencies, and assignment settings. This provides greater control than many simpler application deployment methods. Microsoft Store apps are distributed through the Microsoft Store integration, while web apps provide shortcuts or access to web-based applications. Win32 apps are therefore commonly selected when an organization needs detailed control over deployment of traditional Windows software.
Question 110
Which Intune application capability allows an administrator to specify that one application must be installed before another application can be deployed?
- Detection rules
- Assignment filters
- Dependencies
- Scope tags
Correct Answer: 3
Explanation
Application dependencies allow Intune administrators to define prerequisite applications that must be installed before a dependent application can be installed. This is useful when software requires supporting components, frameworks, or other applications to function correctly. Intune can use the dependency configuration to establish the appropriate installation sequence. Detection rules determine whether an application is already installed, assignment filters refine targeting, and scope tags control administrative visibility. Dependencies therefore provide the mechanism for defining relationships between applications during managed software deployment.
Question 111
Which Intune action should an administrator use when a corporate-owned Windows device is being reassigned to another employee and the organization wants to preserve its Microsoft Entra identity?
- Wipe
- Autopilot Reset
- Retire
- Remote lock
Correct Answer: 2
Explanation
Autopilot Reset is designed to prepare a Windows device for reuse while preserving important organizational configuration and identity information. It removes user-specific data, applications, and settings while keeping the device managed and ready for another user. This makes it useful when corporate devices are reassigned internally. A full Wipe removes the device’s contents more completely, Retire removes organizational management and corporate data, and Remote lock simply prevents normal access. Autopilot Reset is therefore suitable when a managed Windows device needs to be quickly prepared for another employee.
Question 112
Which Windows feature provides a protected environment where administrators can test potentially untrusted applications without affecting the host operating system?
- Windows Sandbox
- Storage Sense
- Credential Guard
- BitLocker
Correct Answer: 1
Explanation
Windows Sandbox provides a lightweight, isolated desktop environment that can be used to run applications without making permanent changes to the host Windows installation. It is useful for testing software, opening potentially untrusted files, or evaluating configuration behavior in a temporary environment. When the Sandbox session is closed, its temporary environment is discarded. Credential Guard protects sensitive authentication information, BitLocker encrypts storage, and Storage Sense manages disk space. Windows Sandbox is therefore the appropriate feature when administrators need an isolated environment for temporary application testing.
Question 113
Which Intune capability can be used to configure Windows devices with a standardized collection of recommended security settings?
- Security baseline
- Application assignment
- Device category
- Enrollment Status Page
Correct Answer: 1
Explanation
Intune security baselines provide standardized collections of recommended security settings for supported Windows devices. Administrators can deploy a baseline to targeted groups and customize settings where organizational requirements differ from the recommended configuration. Security baselines can help establish consistent protections across many endpoints and simplify security configuration. Application assignments are used for software deployment, device categories classify devices, and the Enrollment Status Page controls aspects of device setup. A security baseline is therefore the appropriate Intune capability when an organization wants to establish a consistent recommended security posture.
Question 114
A managed Windows device repeatedly fails a compliance requirement because its firewall is disabled. Which policy should define the firewall requirement?
- Application protection policy
- Compliance policy
- Device cleanup rule
- App configuration policy
Correct Answer: 2
Explanation
An Intune compliance policy can include security requirements such as whether the firewall is enabled. When the device fails the requirement, Intune can mark it as noncompliant and apply configured compliance actions. Conditional Access can then use the compliance state when determining access to organizational resources. Application protection policies protect data within supported applications, device cleanup rules manage stale device records, and app configuration policies configure application settings. Therefore, the compliance policy should define the requirement that the Windows firewall must be enabled.
Question 115
Which Intune feature can be used to configure Windows settings through a graphical catalog containing many individual device settings?
- Enrollment restrictions
- Settings Catalog
- Device cleanup
- Remote Help
Correct Answer: 2
Explanation
The Intune Settings Catalog provides administrators with a searchable collection of individual configuration settings for supported devices. Administrators can select the settings they need, configure their values, and deploy them through policy assignments. This approach provides granular control and makes it easier to locate specific settings without manually creating custom configuration definitions for every requirement. Enrollment restrictions control device enrollment, device cleanup removes stale records, and Remote Help supports remote troubleshooting. The Settings Catalog is therefore the appropriate feature when administrators need detailed, centralized control over individual Windows settings.
Question 116
An organization wants to automatically install a security application on every managed Windows device in a specific device group. Which assignment type should be used?
- Available
- Required
- Uninstall
- Excluded
Correct Answer: 2
Explanation
A Required application assignment instructs Intune to install the application automatically on targeted users or devices. This is appropriate when an organization considers the application mandatory, such as an endpoint security agent or another essential business application. An Available assignment allows users to install the application voluntarily through Company Portal. An Uninstall assignment removes the application from targeted devices, while an exclusion prevents selected users or devices from receiving the assignment. Therefore, Required is the appropriate assignment type when the application must be installed automatically.
Question 117
Which Windows security technology helps prevent unauthorized applications from executing by using organizational application control policies?
- Storage Sense
- Delivery Optimization
- App Control for Business
- Windows Update
Correct Answer: 3
Explanation
App Control for Business provides application control capabilities that allow organizations to establish rules governing which applications can execute on managed Windows devices. It can help restrict unauthorized or untrusted software while permitting approved applications. This supports a stronger application control strategy than relying only on malware detection. Storage Sense manages storage space, Delivery Optimization manages update content distribution, and Windows Update handles operating system servicing. App Control for Business is therefore the appropriate security technology when an organization needs policy-based control over application execution.
Question 118
Which Intune capability helps administrators identify devices that have poor startup performance and may negatively affect user productivity?
- Endpoint analytics
- App protection policies
- Device enrollment restrictions
- Microsoft Store
Correct Answer: 1
Explanation
Endpoint analytics provides insights into device performance and user experience, including startup performance. Administrators can use its information to identify devices that take longer than expected to become usable and investigate possible causes. This can help organizations identify configuration, hardware, or software issues affecting productivity. App protection policies protect organizational information inside supported applications, enrollment restrictions control which devices can enroll, and Microsoft Store provides application distribution capabilities. Endpoint analytics is therefore the Intune capability most directly associated with identifying and analyzing poor device startup performance.
Question 119
Which Intune feature allows administrators to configure policies that automatically apply to users or devices based on membership in Microsoft Entra groups?
- Windows Sandbox
- Group-based assignment
- Device wipe
- Security baseline
Correct Answer: 2
Explanation
Group-based assignment allows Intune administrators to target applications, configuration profiles, compliance policies, and other management objects to Microsoft Entra users or device groups. When users or devices become members of the targeted groups, the assigned policies or applications can be applied according to Intune processing and assignment rules. This makes group membership an important foundation for scalable endpoint management. Windows Sandbox provides isolation, device wipe removes data, and security baselines provide security configurations. Group-based assignment is therefore the appropriate mechanism for targeting Intune resources through Microsoft Entra groups.
Question 120
Which Intune capability allows administrators to collect and inspect information from a Windows device to help investigate configuration or management problems?
- Device query
- Storage Sense
- Company Portal
- Update ring
Correct Answer: 1
Explanation
Device query allows administrators to retrieve information from supported managed Windows devices to assist with investigation and troubleshooting. Administrators can query device information and use the returned data to understand the current state of endpoints without relying entirely on manual inspection. This can help identify configuration issues, hardware information, or other conditions relevant to endpoint management. Storage Sense manages disk space, Company Portal provides user-facing application and device functions, and update rings control Windows Update behavior. Device query is therefore the appropriate capability for collecting endpoint information during troubleshooting.