View Full Microsoft MD-102 Exam Dumps and Practice Test Dumps.
Question 221
Which Microsoft Intune feature allows administrators to configure policies for devices based on whether they are corporate-owned or personally owned?
- Device ownership
- Scope tags
- Device query
- Endpoint analytics
Correct Answer: 1
Explanation
Device ownership identifies whether a managed device is corporate-owned or personally owned. This information can be used in Intune management scenarios where different policies, restrictions, or application requirements apply depending on ownership. Corporate-owned devices may receive broader management controls, while personally owned devices can be managed with more limited configurations to protect user privacy. Scope tags control administrative visibility, Device query retrieves device information, and Endpoint analytics provides performance insights. Device ownership is therefore the appropriate capability when management behavior needs to distinguish between corporate and personally owned endpoints.
Question 222
Which Windows Autopilot capability allows an administrator to associate a physical device with an organization before deployment?
- Enrollment Status Page
- Windows Autopilot device registration
- Update ring
- Remote Help
Correct Answer: 2
Explanation
Windows Autopilot device registration associates a device’s hardware identity with an organization’s Autopilot service so that the device can receive the appropriate deployment profile during setup. Registration is an important preparation step for organizations using Autopilot to automate Windows provisioning. The Enrollment Status Page controls and displays deployment progress, update rings manage Windows Update behavior, and Remote Help provides remote assistance. Device registration is therefore the appropriate capability when an organization needs to identify a physical device to the Autopilot service before deployment.
Question 223
Which Intune feature allows administrators to restrict enrollment based on operating system platform or device ownership?
- Assignment filters
- Enrollment restrictions
- Compliance policies
- Security baselines
Correct Answer: 2
Explanation
Enrollment restrictions allow administrators to control which platforms and device ownership types can enroll in Intune. Organizations can use these restrictions to prevent unsupported operating systems or unwanted personally owned devices from entering management. This helps ensure that only approved device types are enrolled according to organizational requirements. Assignment filters refine the targeting of policies after enrollment, compliance policies evaluate device conditions, and security baselines provide recommended security configurations. Enrollment restrictions are therefore the correct feature when administrators need to control which types of devices are permitted to enroll.
Question 224
Which Intune policy type is designed to configure settings for applications such as Microsoft 365 Apps on managed devices?
- App configuration policy
- Compliance policy
- Device cleanup policy
- Remote lock policy
Correct Answer: 1
Explanation
App configuration policies allow administrators to configure supported application settings on managed devices. These policies can provide application-specific configuration values without requiring users to manually configure the application. They are useful for standardizing application behavior across organizational endpoints and can be used with supported Microsoft applications and other managed applications. Compliance policies evaluate device conditions, device cleanup policies manage stale records, and remote lock is a device action rather than an application configuration mechanism. App configuration policy is therefore the appropriate choice for centrally configuring supported application settings.
Question 225
Which Intune capability allows administrators to assign different policies to devices based on attributes without creating separate groups for every condition?
- Scope tags
- Assignment filters
- Device enrollment manager
- Device cleanup rules
Correct Answer: 2
Explanation
Assignment filters allow administrators to refine the targeting of Intune policies and applications using device attributes. This can reduce the need to create and maintain many separate Microsoft Entra groups for different device conditions. An administrator can assign a policy to a broad group and then use a filter to include or exclude devices that meet specified criteria. Scope tags control administrative visibility, Device Enrollment Manager supports enrollment of multiple devices, and cleanup rules remove stale records. Assignment filters are therefore useful for flexible and attribute-based policy targeting.
Question 226
A company wants to deploy Microsoft 365 Apps to all managed Windows devices in a specific department. Which Intune capability should be used to target the deployment?
- Microsoft Entra group assignment
- Device cleanup
- Remote Help
- Windows LAPS
Correct Answer: 1
Explanation
Microsoft Entra group assignment allows administrators to target applications and policies to specific groups of users or devices. For a Microsoft 365 Apps deployment, the administrator can create or use an appropriate department-based group and assign the application to that group through Intune. Only members of the targeted group will receive the deployment according to the assignment configuration and applicable filters. Device cleanup manages stale records, Remote Help supports assistance, and Windows LAPS manages local administrator passwords. Group assignment is therefore the appropriate targeting method for this deployment scenario.
Question 227
Which Intune feature allows administrators to configure settings for Microsoft Edge across managed Windows devices using supported policy templates?
- Administrative templates
- Device cleanup rules
- Compliance actions
- Device categories
Correct Answer: 1
Explanation
Administrative templates provide a policy-based method for configuring supported application and Windows settings through Intune. They are particularly useful for managing Microsoft Edge settings consistently across organizational Windows devices. Administrators can select supported policy settings, configure their values, and assign the resulting profile to users or devices. Device cleanup rules handle stale device records, compliance actions respond to noncompliance, and device categories help classify endpoints. Administrative templates are therefore an appropriate choice when centralized Microsoft Edge configuration is required.
Question 228
Which Windows feature can prevent unauthorized applications from accessing protected folders where sensitive files are stored?
- SmartScreen
- Controlled folder access
- Delivery Optimization
- Storage Sense
Correct Answer: 2
Explanation
Controlled folder access is a Microsoft Defender Antivirus security feature designed to protect specified folders from unauthorized changes by potentially malicious applications. It can help prevent ransomware and other threats from modifying protected files. Administrators can configure supported Controlled folder access settings through Intune endpoint security policies. SmartScreen focuses on reputation-based protection, Delivery Optimization manages update and application content distribution, and Storage Sense manages disk space. Controlled folder access is therefore the appropriate feature when the goal is to restrict unauthorized application access to protected folders.
Question 229
Which Microsoft Intune capability allows administrators to define actions that occur when a device becomes noncompliant?
- Compliance policy actions
- Security baseline
- Assignment filter
- Device category
Correct Answer: 1
Explanation
Compliance policy actions allow administrators to define what happens when a device fails compliance requirements. Actions can include marking the device noncompliant and applying configured enforcement behavior after specified conditions or grace periods. These actions can work with Conditional Access and other identity controls to help protect organizational resources. Security baselines configure recommended security settings, assignment filters refine policy targeting, and device categories classify devices. Compliance policy actions are therefore the appropriate mechanism for defining responses to device noncompliance.
Question 230
Which Intune application type is commonly used to deploy a traditional Windows desktop application packaged by an administrator?
- Web app
- Win32 app
- Microsoft Store app
- Built-in Windows feature
Correct Answer: 2
Explanation
Win32 apps in Intune are designed for deploying traditional Windows desktop applications that administrators package and manage through Intune. Administrators can configure installation commands, requirements, detection rules, dependencies, return codes, and other deployment settings. This provides substantial control over application deployment for enterprise environments. Web apps primarily provide shortcuts or access to web-based applications, while Microsoft Store apps use the supported Store integration. A built-in Windows feature does not represent an Intune application deployment type. Win32 app is therefore the appropriate option for traditional packaged desktop software.
Question 231
Which Intune feature can ensure that a prerequisite application is installed before another Win32 application is deployed?
- Supersedence
- Dependency
- Detection rule
- Assignment filter
Correct Answer: 2
Explanation
Win32 application dependencies allow administrators to specify applications that must be installed before another application can be successfully deployed. Intune evaluates the dependency relationship and attempts to install the prerequisite application before installing the dependent application. This is useful when business software requires supporting components or runtimes. Supersedence manages application replacement, detection rules determine whether an application is installed, and assignment filters control targeting. Dependency is therefore the appropriate feature when an application must have another application installed first.
Question 232
Which Windows security feature uses virtualization-based security to isolate sensitive operating system components from the normal Windows environment?
- Virtualization-based security
- Storage Sense
- Windows Update
- File History
Correct Answer: 1
Explanation
Virtualization-based security, or VBS, uses hardware virtualization capabilities to create isolated security environments within Windows. Security features such as Credential Guard can use VBS to help protect sensitive information from threats operating in the normal Windows environment. VBS strengthens endpoint protection by separating selected security functions from ordinary operating system processes. Storage Sense manages storage, Windows Update provides operating system updates, and File History provides file backup functionality. Virtualization-based security is therefore the appropriate choice when the requirement involves isolating sensitive security components using virtualization.
Question 233
Which Intune feature provides administrators with a centralized view of device configuration and management information for troubleshooting?
- Device inventory
- Enrollment restriction
- App assignment
- Device category
Correct Answer: 1
Explanation
Device inventory provides administrators with information about managed devices and their relevant hardware and software characteristics. This information can assist with troubleshooting, asset management, application planning, and security investigations. Inventory data can help administrators identify device models, operating system information, and other supported attributes without manually inspecting every endpoint. Enrollment restrictions determine which devices may enroll, app assignments control software deployment, and device categories classify devices for management purposes. Device inventory is therefore the appropriate capability when administrators need centralized endpoint information for troubleshooting and management.
Question 234
Which Intune feature allows administrators to configure Windows update settings such as active hours and restart behavior?
- Feature update policy
- Update ring
- Security baseline
- App protection policy
Correct Answer: 2
Explanation
Update rings provide configuration options for the Windows Update experience, including settings related to update deferrals, active hours, restart behavior, notifications, and other servicing controls. They are useful for defining how Windows devices receive and process regular updates across different deployment groups. Feature update policies primarily control the target Windows feature release, security baselines focus on security configuration, and app protection policies protect organizational data within supported applications. Update rings are therefore the appropriate feature when administrators need to control active hours and restart behavior for Windows updates.
Question 235
Which Microsoft Intune capability allows administrators to immediately request a supported quality update instead of waiting for the normal update schedule?
- Expedite update policy
- Device cleanup rule
- Device category
- Security baseline
Correct Answer: 1
Explanation
Expedite update policies are designed to accelerate the deployment of specific Windows quality updates when an organization needs devices to receive an update more quickly than their normal servicing schedule. This can be useful when Microsoft releases an important security update and administrators want supported devices to install it promptly. Device cleanup rules manage stale records, device categories organize devices, and security baselines configure recommended security settings. Expedite update policy is therefore the appropriate capability when administrators need to accelerate deployment of a specified quality update.
Question 236
Which Intune capability helps administrators delegate management responsibilities by limiting what specific administrators can view or manage?
- Scope tags
- Device query
- Update rings
- App protection policies
Correct Answer: 1
Explanation
Scope tags help organizations control which Intune objects administrators can view and manage when used with appropriate role-based access control configurations. They are useful in environments where different administrative teams are responsible for different regions, departments, or groups of devices. Device query retrieves device information, update rings manage Windows Update behavior, and app protection policies protect organizational data within supported applications. Scope tags therefore support delegated administration by limiting administrative visibility to appropriately tagged resources when combined with suitable Intune roles.
Question 237
Which Intune security policy category is specifically intended to configure Microsoft Defender Firewall settings?
- Account protection
- Disk encryption
- Firewall
- Antivirus
Correct Answer: 3
Explanation
The Firewall endpoint security policy category in Intune is designed to configure supported Microsoft Defender Firewall settings on managed devices. Administrators can use these policies to establish firewall behavior and network protection requirements across organizational endpoints. Account protection focuses on account and authentication-related security, disk encryption manages technologies such as BitLocker, and antivirus policies configure malware protection settings. Firewall is therefore the correct policy category when an organization needs to centrally configure Microsoft Defender Firewall on managed Windows devices.
Question 238
Which Windows management scenario allows an organization to continue using Configuration Manager while gradually moving management workloads to Intune?
- Co-management
- Device registration
- Windows Sandbox
- Self-deploying mode
Correct Answer: 1
Explanation
Co-management allows organizations to manage Windows devices using both Microsoft Configuration Manager and Microsoft Intune while workloads can gradually transition toward cloud-based management. Administrators can determine which management solution handles specific workloads and progressively move responsibilities as the organization’s requirements change. Device registration establishes a device identity, Windows Sandbox provides an isolated testing environment, and self-deploying mode is a Windows Autopilot deployment option. Co-management is therefore the appropriate scenario when an organization wants to maintain Configuration Manager while adopting Intune management capabilities.
Question 239
Which Microsoft Intune feature can help identify whether a device meets hardware requirements for a supported Windows deployment?
- Endpoint analytics
- Hardware inventory
- Company Portal
- Remote lock
Correct Answer: 2
Explanation
Hardware inventory provides information about managed devices that can help administrators assess hardware characteristics relevant to Windows deployment and management. Information such as processor details, memory, storage, and other supported hardware attributes can assist with readiness assessments and deployment planning. Endpoint analytics focuses more broadly on device performance and user experience, Company Portal provides user-facing application and management functionality, and Remote lock restricts device access. Hardware inventory is therefore the appropriate capability when administrators need endpoint hardware information to evaluate deployment readiness.
Question 240
Which Intune feature allows administrators to configure a policy that protects corporate data inside supported mobile applications without fully managing the user’s personal device?
- Mobile application management
- Windows Autopilot
- Device cleanup
- Update ring
Correct Answer: 1
Explanation
Mobile application management, commonly implemented through Intune app protection policies, allows organizations to protect corporate data within supported applications without necessarily requiring full device enrollment. This approach is particularly useful for personally owned devices where an organization wants to control business data while limiting management of personal information. Windows Autopilot is designed for Windows provisioning, device cleanup manages stale records, and update rings control Windows Update behavior. Mobile application management is therefore the appropriate capability when protecting organizational data inside supported applications is the primary requirement.