View Full Microsoft MD-102 Exam Dumps and Practice Test Dumps.
Question 261
Which Intune capability can automatically enroll eligible Windows devices into mobile device management after a user signs in with an organizational account?
- Device cleanup
- Scope tags
- Company Portal
- Automatic MDM enrollment
Correct Answer: 4
Explanation
Automatic MDM enrollment allows eligible Windows devices to enroll into Intune when users sign in with organizational identities, provided the required Microsoft Entra and enrollment configuration is in place. Administrators can define the appropriate MDM user scope so that selected users receive automatic enrollment without manually starting the process. Device cleanup manages stale device records, scope tags control administrative visibility, and Company Portal provides user-facing management functionality. Automatic MDM enrollment is therefore the appropriate capability when Windows devices should enter Intune management automatically after an eligible user signs in.
Question 262
Which Microsoft Intune capability allows administrators to configure policies specifically for local administrator account protection?
- Account protection
- Antivirus
- Firewall
- Disk encryption
Correct Answer: 1
Explanation
The Account protection category within Intune endpoint security provides settings related to account security and supported authentication protections on Windows devices. It can be used to configure policies that strengthen local account security and other supported identity-related protections. Antivirus policies manage malware protection, Firewall policies configure network traffic controls, and Disk encryption policies manage technologies such as BitLocker. Account protection is therefore the appropriate endpoint security category when administrators need to configure supported local administrator and account security settings across managed Windows devices.
Question 263
An administrator needs to make an application available for users to install from Company Portal but does not want it installed automatically. Which assignment should be used?
- Required
- Uninstall
- Available
- Dependency
Correct Answer: 3
Explanation
An Available assignment makes an application visible to targeted users through Company Portal without automatically installing it. Users can open Company Portal, review the available application, and choose to install it when needed. This assignment type is useful for optional business applications that are not required on every device. Required assignments automatically deploy applications, Uninstall assignments remove applications, and dependencies establish prerequisite relationships between applications. Available is therefore the correct assignment type when users should have access to optional software but installation should remain under their control.
Question 264
Which Intune feature can configure a Windows device to use a specific version of Windows 11 rather than immediately moving to newer feature releases?
- Update ring
- Feature update policy
- Compliance policy
- Security baseline
Correct Answer: 2
Explanation
A feature update policy allows administrators to specify a target Windows feature update version for managed devices. This helps organizations control Windows servicing and keep devices on an approved release while administrators test newer versions. Update rings manage broader Windows Update behavior, including deferrals and restart settings, but they do not primarily establish a specific target feature version. Compliance policies evaluate whether devices satisfy requirements, while security baselines configure recommended security settings. Feature update policy is therefore the appropriate Intune capability for controlling the Windows feature version installed on managed devices.
Question 265
Which Intune feature provides a predefined collection of Microsoft-recommended security settings for Windows devices?
- App protection policy
- Configuration profile
- Security baseline
- Device category
Correct Answer: 3
Explanation
Security baselines provide predefined collections of recommended security settings that organizations can deploy to supported Windows devices through Intune. Administrators can review the baseline, determine which settings are appropriate, modify supported values where necessary, and assign the policy to targeted users or devices. App protection policies protect organizational data within supported applications, configuration profiles provide broader device configuration capabilities, and device categories classify endpoints. Security baseline is therefore the correct choice when an organization wants to establish a standardized set of recommended Windows security configurations.
Question 266
Which Windows Autopilot mode is designed for devices such as kiosks or shared computers where no individual user needs to perform the initial setup?
- User-driven mode
- Pre-provisioning
- Self-deploying mode
- Hybrid deployment
Correct Answer: 3
Explanation
Windows Autopilot self-deploying mode is designed for scenarios where a device needs to be provisioned without requiring a user to authenticate during the initial deployment. It is suitable for shared devices, kiosks, and similar scenarios where the endpoint is prepared for organizational use rather than assigned through a traditional user-driven setup. User-driven mode requires user interaction, while pre-provisioning allows a technician to prepare the device before delivery. Hybrid deployment is not the primary Autopilot mode for this purpose. Self-deploying mode therefore matches the described deployment scenario.
Question 267
Which Intune capability allows an administrator to view information such as device manufacturer, model, and operating system version?
- Device inventory
- Assignment filter
- Compliance action
- Scope tag
Correct Answer: 1
Explanation
Device inventory provides administrators with information about managed endpoints, including supported hardware and software characteristics such as manufacturer, model, and operating system information. This information can help with asset management, troubleshooting, application planning, and deployment preparation. Assignment filters are used to refine policy targeting, compliance actions define responses to noncompliance, and scope tags control administrative visibility. Device inventory is therefore the appropriate Intune capability when administrators need centralized information about the characteristics of managed devices.
Question 268
Which Intune feature allows an administrator to specify that a device must have a particular Windows version before a Win32 application can be installed?
- Detection rule
- Requirement rule
- Supersedence
- Dependency
Correct Answer: 2
Explanation
Win32 application requirement rules define conditions that a device must meet before Intune installs the application. Administrators can configure supported requirements such as operating system version, architecture, disk space, and other applicable conditions. This ensures that software is not deployed to devices that do not meet its technical requirements. Detection rules determine whether an application is already installed, supersedence manages replacement of older applications, and dependencies identify prerequisite applications. Requirement rule is therefore the appropriate feature when installation must depend on a specific Windows operating system version.
Question 269
Which Intune feature can be used to protect corporate data in mobile applications without requiring the entire personal device to be enrolled?
- Device enrollment restriction
- Update ring
- App protection policy
- Windows Autopilot
Correct Answer: 3
Explanation
App protection policies support mobile application management by applying data protection controls directly within supported applications. This allows organizations to protect corporate information on personally owned devices without necessarily requiring full device enrollment into Intune. Administrators can configure restrictions on actions such as copy and paste, data transfer, and saving organizational information. Enrollment restrictions control which devices can enroll, update rings manage Windows Update behavior, and Windows Autopilot provisions Windows devices. App protection policy is therefore the appropriate capability for protecting corporate application data without full device management.
Question 270
Which Intune feature can be used to configure settings that control how Windows devices receive and install regular quality updates?
- Security baseline
- Compliance policy
- Feature update policy
- Update ring
Correct Answer: 4
Explanation
Update rings provide controls for the Windows Update experience, including quality update deferrals, restart behavior, active hours, notifications, and other supported servicing settings. Organizations can use different update rings for testing, pilot, and broader deployment groups. Feature update policies are used to control the target Windows feature version, while security baselines and compliance policies address security configuration and evaluation rather than general update behavior. Update ring is therefore the appropriate Intune feature when administrators need to control how managed Windows devices receive and process regular quality updates.
Question 271
Which Microsoft Intune feature can be used to remotely restart a managed Windows device?
- Device action
- Security baseline
- Assignment filter
- Scope tag
Correct Answer: 1
Explanation
Intune provides remote device actions that administrators can use to perform supported operations on managed endpoints, including restarting a device. Remote actions can help administrators troubleshoot devices or apply changes without requiring physical access to the endpoint. Security baselines configure security settings, assignment filters refine policy targeting, and scope tags control administrative visibility. A device action is therefore the appropriate mechanism when an administrator needs to remotely restart a managed Windows device. The action should be used carefully because restarting can interrupt active work on the endpoint.
Question 272
Which Intune feature allows administrators to configure a device policy by entering a custom OMA-URI setting?
- Settings Catalog
- Custom configuration profile
- Security baseline
- Update ring
Correct Answer: 2
Explanation
A custom configuration profile can use OMA-URI settings to configure supported Windows management settings that may not be available through standard Intune policy interfaces. Administrators specify the OMA-URI path, data type, and corresponding value to deliver the configuration to managed devices. This approach provides additional flexibility but requires accurate knowledge of the supported setting and syntax. Settings Catalog provides a searchable collection of exposed settings, security baselines provide recommended security configurations, and update rings manage Windows Update behavior. A custom configuration profile is therefore appropriate for custom OMA-URI configuration.
Question 273
Which Intune capability can determine whether a managed device is encrypted before it is considered compliant?
- Compliance policy
- App configuration policy
- Device category
- Scope tag
Correct Answer: 1
Explanation
Compliance policies can evaluate supported device requirements, including encryption status, to determine whether a managed device satisfies organizational security standards. Administrators can configure encryption requirements and use the resulting compliance state with Conditional Access to help control access to protected resources. App configuration policies manage application settings, device categories classify devices, and scope tags control administrative visibility. Compliance policy is therefore the correct capability when an organization needs to evaluate whether a device meets an encryption requirement as part of its compliance status.
Question 274
Which Microsoft Intune capability allows administrators to create policies that configure Microsoft Defender Firewall behavior?
- Antivirus policy
- Account protection policy
- Firewall policy
- Disk encryption policy
Correct Answer: 3
Explanation
The Firewall endpoint security policy in Intune is designed to configure Microsoft Defender Firewall settings on supported Windows devices. Administrators can use it to establish network protection requirements and manage supported firewall behavior across managed endpoints. Antivirus policies configure malware protection, Account protection policies focus on account and authentication security, and Disk encryption policies manage technologies such as BitLocker. Firewall policy is therefore the appropriate endpoint security policy when the goal is to centrally configure Microsoft Defender Firewall across organizational Windows devices.
Question 275
Which Microsoft Entra capability automatically updates device group membership based on a defined membership rule?
- Static group
- Dynamic device group
- Scope tag
- Device category
Correct Answer: 2
Explanation
Dynamic device groups automatically manage membership based on defined rules and device attributes. When a device meets the configured rule, it can be added to the group, and when it no longer satisfies the rule, membership can change accordingly. This makes dynamic groups useful for automatically targeting Intune policies, applications, and compliance configurations. Static groups require manual membership management, scope tags control administrative visibility, and device categories classify devices. Dynamic device groups are therefore the appropriate Microsoft Entra capability when group membership should be maintained automatically according to device attributes.
Question 276
Which Intune feature can help an administrator identify why a device has not received a recently assigned policy by manually initiating a check-in?
- Device cleanup
- Sync
- Wipe
- Retire
Correct Answer: 2
Explanation
The Sync action causes a managed device to contact the Intune service and check for available policy, application, and configuration changes. Administrators commonly use Sync during troubleshooting when a newly assigned policy has not yet appeared on a device. This can help determine whether the device receives the configuration after a fresh check-in. Device cleanup manages stale records, Wipe resets the device according to the selected options, and Retire removes organizational management and data while generally preserving personal information. Sync is therefore the appropriate troubleshooting action for initiating a policy check-in.
Question 277
Which Windows security feature can use a hardware-backed security component to support BitLocker and Windows Hello for Business?
- SmartScreen
- TPM
- Storage Sense
- File History
Correct Answer: 2
Explanation
The Trusted Platform Module, or TPM, is a hardware-based security component that can securely store cryptographic information and support several Windows security technologies. BitLocker can use TPM capabilities to protect encryption keys and help verify device integrity, while Windows Hello for Business can also use TPM-backed credentials on supported devices. SmartScreen provides reputation-based protection, Storage Sense manages storage, and File History provides file backup. TPM is therefore the appropriate technology when the requirement involves hardware-backed security for BitLocker and Windows Hello for Business.
Question 278
Which Intune capability is designed to provide performance and user-experience insights for managed Windows devices?
- Endpoint analytics
- Device cleanup
- Enrollment restrictions
- Scope tags
Correct Answer: 1
Explanation
Endpoint analytics provides insights into the performance and user experience of managed Windows devices. It can help administrators identify areas such as startup performance, application reliability, and other endpoint-related issues that may affect productivity. This information can support troubleshooting and help organizations prioritize improvements across their managed environment. Device cleanup manages stale records, enrollment restrictions control which devices can enroll, and scope tags limit administrative visibility. Endpoint analytics is therefore the appropriate capability when administrators need information about endpoint performance and the user experience.
Question 279
Which Intune application feature allows a newer Win32 application package to replace an older package?
- Dependency
- Requirement rule
- Supersedence
- Detection rule
Correct Answer: 3
Explanation
Supersedence allows administrators to configure relationships in which a newer Win32 application replaces an older version or application package. This capability simplifies application lifecycle management by providing a controlled way to upgrade or replace existing software deployments. Dependencies identify applications that must be installed first, requirement rules determine whether a device qualifies for installation, and detection rules determine whether an application is already installed. Supersedence is therefore the correct feature when administrators need a newer Win32 application package to replace an older deployment.
Question 280
Which Intune action is designed to remove organizational data and management from a device while generally leaving personal data intact?
- Wipe
- Retire
- Restart
- Remote lock
Correct Answer: 2
Explanation
The Retire action removes organizational management and supported corporate data from a managed device while generally preserving the user’s personal information. It is especially useful for personally owned devices when an employee no longer requires access to organizational resources. Wipe performs a broader reset that can remove device data, Restart simply reboots the endpoint, and Remote lock restricts access without removing organizational data. Retire is therefore the appropriate Intune action when an organization needs to remove its management and corporate information while preserving personal user data.