View Full Microsoft MD-102 Exam Dumps and Practice Test Dumps.
Question 321
Which Intune feature allows administrators to control whether personally owned Windows devices can enroll?
- Enrollment restrictions
- Device cleanup rules
- Scope tags
- Update rings
Correct Answer: 1
Explanation
Enrollment restrictions allow Intune administrators to control which types of devices can enroll into device management. Administrators can configure platform restrictions and ownership-related settings to prevent unsupported or unwanted devices from enrolling. This is particularly useful when an organization wants to restrict personally owned Windows devices while allowing corporate-owned endpoints. Device cleanup rules remove stale records, scope tags control administrative visibility, and update rings manage Windows Update behavior. Enrollment restrictions are therefore the appropriate feature for controlling which device types and ownership categories are permitted to enroll in Intune.
Question 322
Which Microsoft Entra device state is commonly used when a user adds a personal device for access to organizational resources without fully joining it to the organization?
- Microsoft Entra joined
- Microsoft Entra registered
- Microsoft Entra hybrid joined
- Device Enrollment Manager
Correct Answer: 2
Explanation
Microsoft Entra registered is commonly used for personally owned devices that need an organizational identity for accessing resources without becoming fully joined to the organization’s Microsoft Entra environment. This model supports bring-your-own-device scenarios and can work with additional management or application protection controls. Microsoft Entra joined is intended for devices fully joined to the cloud identity environment, while hybrid joined combines on-premises Active Directory with Microsoft Entra ID. Device Enrollment Manager is an enrollment role rather than a device identity state. Microsoft Entra registered is therefore correct.
Question 323
Which Windows Autopilot capability allows an IT technician or partner to prepare a device before it is delivered to the end user?
- Self-deploying mode
- User-driven deployment
- Pre-provisioning
- Device cleanup
Correct Answer: 3
Explanation
Windows Autopilot pre-provisioning allows an IT technician, reseller, or other authorized party to prepare a device before delivering it to the end user. During pre-provisioning, required applications, policies, and organizational configurations can be applied before the user receives the device. This can reduce the amount of setup the user must complete during first sign-in. User-driven deployment requires user participation, while self-deploying mode is intended for scenarios where user authentication is not required during provisioning. Pre-provisioning is therefore the appropriate choice for technician-assisted preparation.
Question 324
Which Intune application assignment type automatically installs an application on targeted managed devices?
- Available
- Uninstall
- Required
- Dependency
Correct Answer: 3
Explanation
A Required application assignment instructs Intune to automatically deploy an application to the targeted users or devices. This assignment type is appropriate for mandatory applications such as security agents, business software, or organizational tools that every applicable endpoint must have. Available assignments allow users to install applications from Company Portal when needed. Uninstall assignments remove applications, while dependencies identify prerequisite applications. Required is therefore the correct assignment type when administrators need an application to be automatically installed on targeted managed devices.
Question 325
Which Windows management technology enables mobile device management policies to be applied to Windows without traditional Group Policy?
- MDM
- SMB
- DNS
- NTFS
Correct Answer: 1
Explanation
Mobile Device Management, or MDM, allows Windows devices to receive management policies through modern cloud-based management platforms such as Microsoft Intune. MDM uses supported management interfaces to configure settings, enforce security requirements, deploy applications, and perform management actions without requiring traditional domain-based Group Policy for every configuration. SMB is a file and printer sharing protocol, DNS provides name resolution, and NTFS is a Windows file system. MDM is therefore the correct technology for applying modern Windows management policies through Intune.
Question 326
Which Intune feature can use a device attribute to include or exclude devices from a policy assignment without changing group membership?
- Security baseline
- Assignment filter
- Device category
- Compliance policy
Correct Answer: 2
Explanation
Assignment filters allow administrators to refine Intune policy and application assignments based on device attributes. They can be used to include or exclude devices from an assignment without requiring administrators to modify the underlying Microsoft Entra group membership. This provides more precise targeting for configuration profiles, applications, compliance policies, and other supported workloads. Security baselines provide predefined security configurations, device categories classify devices, and compliance policies evaluate device requirements. Assignment filters are therefore the appropriate feature for refining assignments according to device attributes.
Question 327
Which Windows feature can automatically manage local administrator passwords by generating and rotating unique passwords?
- Windows Hello for Business
- Windows LAPS
- Credential Guard
- BitLocker
Correct Answer: 2
Explanation
Windows LAPS, or Windows Local Administrator Password Solution, manages local administrator passwords by securely generating, storing, and rotating passwords according to configured policies. This helps reduce the security risks associated with using identical or static local administrator credentials across multiple devices. Windows Hello for Business provides passwordless authentication, Credential Guard helps protect authentication credentials, and BitLocker provides disk encryption. Windows LAPS is therefore the appropriate feature when an organization needs centralized management and regular rotation of local administrator passwords on Windows devices.
Question 328
Which Intune feature provides users with a self-service location for installing applications that have been assigned as available?
- Company Portal
- Endpoint analytics
- Settings Catalog
- Windows Autopilot
Correct Answer: 1
Explanation
Company Portal provides users with a self-service interface for accessing applications, devices, and supported organizational resources managed through Intune. When an application is assigned as Available, users can typically locate it in Company Portal and choose whether to install it. Endpoint analytics focuses on endpoint performance and user experience, Settings Catalog provides administrative configuration options, and Windows Autopilot supports device provisioning. Company Portal is therefore the correct choice when users need a self-service interface for discovering and installing optional applications assigned through Intune.
Question 329
Which Intune feature is specifically designed to deploy Microsoft 365 Apps such as Word, Excel, and PowerPoint to managed Windows devices?
- Web app
- Microsoft 365 Apps
- App protection policy
- Device configuration profile
Correct Answer: 2
Explanation
The Microsoft 365 Apps application type in Intune is designed to deploy supported Microsoft 365 productivity applications to managed devices. Administrators can configure which Office applications and supported settings should be included in the deployment and then assign the application to appropriate users or devices. Web apps provide shortcuts to browser-based resources, app protection policies protect organizational data within supported applications, and configuration profiles manage device settings. Microsoft 365 Apps is therefore the appropriate application type when deploying applications such as Word, Excel, and PowerPoint through Intune.
Question 330
Which Windows feature helps protect files in selected folders from unauthorized modification by potentially malicious applications?
- SmartScreen
- Credential Guard
- Controlled folder access
- Storage Sense
Correct Answer: 3
Explanation
Controlled folder access is a Microsoft Defender feature designed to help protect selected folders against unauthorized changes by potentially malicious applications. It can reduce the impact of ransomware and similar threats by restricting untrusted applications from modifying protected locations. SmartScreen provides reputation-based protection, Credential Guard protects sensitive authentication information, and Storage Sense helps manage disk space. Controlled folder access is therefore the appropriate security feature when the requirement is to prevent unauthorized applications from modifying files in protected folders.
Question 331
Which Intune feature can provide a predefined collection of Microsoft-recommended security configuration settings for Windows devices?
- Security baseline
- Device category
- Assignment filter
- Company Portal
Correct Answer: 1
Explanation
Security baselines provide predefined collections of recommended security settings that administrators can deploy to supported Windows devices. They help organizations establish a consistent security configuration without manually creating every individual setting. Administrators can review and customize supported baseline settings before assigning them to users or devices. Device categories classify endpoints, assignment filters refine targeting, and Company Portal provides user-facing functionality. Security baseline is therefore the correct choice when an organization wants a centralized collection of recommended Windows security configurations.
Question 332
Which Windows Autopilot feature displays deployment progress and can prevent users from accessing the desktop until required configurations are completed?
- Windows LAPS
- Enrollment Status Page
- Endpoint analytics
- Company Portal
Correct Answer: 2
Explanation
The Enrollment Status Page, or ESP, displays deployment progress during Windows Autopilot and enrollment scenarios and can control whether the user is allowed to reach the Windows desktop before required configurations are completed. It can track the installation of required applications and the application of device configurations during provisioning. Windows LAPS manages local administrator passwords, Endpoint analytics provides performance insights, and Company Portal offers user-facing application management. The Enrollment Status Page is therefore the correct feature for controlling and displaying deployment progress during device provisioning.
Question 333
Which Intune policy is primarily used to evaluate whether Windows devices meet requirements rather than directly configure most device settings?
- Compliance policy
- Settings Catalog
- Administrative template
- Security baseline
Correct Answer: 1
Explanation
A compliance policy evaluates whether a managed device satisfies defined organizational requirements. Examples can include operating system version, encryption status, firewall state, antivirus protection, password requirements, and other supported conditions. Compliance policies can also work with Conditional Access to help control access to organizational resources based on device compliance status. Settings Catalog, Administrative Templates, and Security Baselines are primarily configuration mechanisms. Compliance policy is therefore the correct choice when the main requirement is to evaluate whether a device meets defined security or management conditions.
Question 334
Which Intune feature allows administrators to configure Windows settings using traditional policy-style templates for supported settings?
- Device query
- Administrative Templates
- Remote Help
- Device cleanup
Correct Answer: 2
Explanation
Administrative Templates in Intune provide policy-style configuration settings for supported Windows devices. They offer a familiar approach for administrators who have previously managed Windows through traditional Group Policy templates. Administrators can configure supported settings and assign the resulting profile to users or devices. Device query retrieves endpoint information, Remote Help provides remote assistance, and device cleanup manages stale records. Administrative Templates are therefore the appropriate Intune feature when administrators need to configure Windows using template-based policy settings.
Question 335
Which Windows update policy allows administrators to accelerate the installation of a specific quality update when a device needs urgent remediation?
- Update ring
- Feature update policy
- Expedite update policy
- Compliance policy
Correct Answer: 3
Explanation
An Expedite update policy can accelerate the deployment of specific Windows quality updates when organizations need devices to receive an update quickly. This is useful when a particular security update requires rapid deployment rather than waiting for the normal update ring schedule. Update rings control broader Windows Update behavior, feature update policies target Windows feature versions, and compliance policies evaluate device requirements. Expedite update policy is therefore the correct option when administrators need to speed up deployment of a specific quality update across applicable managed devices.
Question 336
Which Intune capability can help administrators remotely assist a user by viewing or controlling a supported managed device?
- Remote Help
- Device cleanup
- Assignment filter
- Scope tag
Correct Answer: 1
Explanation
Remote Help is an Intune capability that allows authorized support personnel to remotely assist users on supported managed devices. It is designed for troubleshooting and support scenarios where an administrator or help-desk technician needs to interact with a user’s device remotely. Device cleanup manages inactive device records, assignment filters refine policy targeting, and scope tags control administrative visibility. Remote Help is therefore the appropriate capability when an organization needs a supported remote assistance solution integrated with its endpoint management environment.
Question 337
Which Intune application mechanism determines whether a Win32 application is already installed on a device?
- Requirement rule
- Detection rule
- Dependency
- Assignment filter
Correct Answer: 2
Explanation
Detection rules determine whether a Win32 application is already installed or otherwise meets the configured detection condition. Intune uses the detection result to determine whether an application installation is required or whether the desired state has already been reached. Requirement rules determine whether the device is eligible for installation, dependencies define prerequisite applications, and assignment filters control targeting. Detection rule is therefore the correct mechanism when administrators need Intune to determine whether a Win32 application is present on a managed device.
Question 338
Which device action is generally appropriate when an administrator needs to immediately reboot a managed Windows device remotely?
- Wipe
- Retire
- Restart
- Fresh Start
Correct Answer: 3
Explanation
The Restart action allows administrators to remotely reboot a managed device without performing a broader device reset or removing organizational management. It can be useful when troubleshooting, completing configuration changes, or applying certain management operations that require a restart. Wipe resets the device and can remove data, Retire removes organizational management while generally preserving personal data, and Fresh Start reinstalls Windows while removing applications according to its configuration. Restart is therefore the appropriate action when the primary requirement is simply to remotely reboot the device.
Question 339
Which Microsoft Intune feature helps administrators identify hardware information such as device model, manufacturer, and operating system details?
- Device inventory
- Remote Help
- Conditional Access
- Security baseline
Correct Answer: 1
Explanation
Device inventory provides administrators with information collected from managed endpoints, including supported hardware and software details. This information can help IT teams identify device models, manufacturers, operating system information, and other endpoint characteristics useful for management and troubleshooting. Remote Help is used for remote assistance, Conditional Access controls resource access based on configured conditions, and security baselines configure security settings. Device inventory is therefore the appropriate Intune capability when administrators need centralized information about managed device hardware and software characteristics.
Question 340
Which Intune capability can automatically assign devices to a Microsoft Entra group based on device properties such as operating system or manufacturer?
- Static group membership
- Dynamic device group
- Device Enrollment Manager
- Scope tag
Correct Answer: 2
Explanation
Dynamic device groups in Microsoft Entra ID can automatically include devices based on defined membership rules that evaluate device properties. Administrators can use attributes such as operating system, manufacturer, model, or other supported properties to create dynamic membership rules. This allows device groups to update automatically as device information changes, reducing manual administration. Static groups require membership to be managed directly, Device Enrollment Manager is an enrollment role, and scope tags control administrative visibility. Dynamic device group is therefore the appropriate solution for property-based automatic device membership.