View Full Microsoft MD-102 Exam Dumps and Practice Test Dumps.
Question 281
Which Microsoft Intune feature allows administrators to control which users or devices can enroll based on platform and ownership settings?
- Device query
- Scope tags
- Assignment filters
- Enrollment restrictions
Correct Answer: 4
Explanation
Enrollment restrictions allow Intune administrators to control which types of devices can enroll in management. Administrators can configure restrictions based on supported operating system platforms and device ownership, helping organizations prevent unwanted or unsupported devices from entering the management environment. Assignment filters are used to refine policy targeting after enrollment, scope tags control administrative visibility, and Device query retrieves information from managed endpoints. Enrollment restrictions are therefore the appropriate feature when an organization needs to determine which platforms or ownership types are permitted to enroll.
Question 282
Which Microsoft Entra device identity provides a cloud-based join that does not require traditional on-premises Active Directory domain membership?
- Microsoft Entra joined
- Microsoft Entra hybrid joined
- Microsoft Entra registered
- Device Enrollment Manager
Correct Answer: 1
Explanation
Microsoft Entra joined devices are joined directly to the organization’s Microsoft Entra environment and do not require membership in a traditional on-premises Active Directory domain. This model is commonly used for cloud-first Windows management and can work closely with Intune for device configuration, application deployment, and compliance management. Microsoft Entra hybrid joined devices maintain an on-premises Active Directory relationship, while Microsoft Entra registered devices represent a lighter registration scenario. Device Enrollment Manager is an Intune enrollment capability rather than a device join type. Microsoft Entra joined is therefore correct.
Question 283
Which Intune feature can configure a Windows device to automatically receive a specific approved Windows feature update version?
- Update ring
- Feature update policy
- Compliance policy
- Endpoint analytics
Correct Answer: 2
Explanation
Feature update policies allow administrators to specify the Windows feature update version that managed devices should receive or remain on. This gives organizations greater control over Windows servicing by allowing IT teams to test a release before deploying it broadly. Update rings manage general update behavior such as deferrals and restart settings, while compliance policies evaluate device requirements. Endpoint analytics provides performance and experience information. Feature update policy is therefore the appropriate Intune capability when an organization wants to control the target Windows feature release on managed devices.
Question 284
Which Intune capability is used to determine whether a Win32 application is already installed on a device?
- Requirement rule
- Dependency
- Detection rule
- Supersedence
Correct Answer: 3
Explanation
Detection rules allow Intune to determine whether a Win32 application is installed successfully on a managed Windows device. Administrators can configure supported detection methods, including file, registry, or MSI-based checks, depending on the application. Intune uses the detection result to determine whether the application needs to be installed or whether the deployment has already completed. Requirement rules determine device eligibility, dependencies identify prerequisite applications, and supersedence manages replacement of applications. Detection rule is therefore the correct capability when Intune needs to verify an application’s installation state.
Question 285
Which Intune endpoint security policy category is used to configure BitLocker settings?
- Antivirus
- Firewall
- Account protection
- Disk encryption
Correct Answer: 4
Explanation
The Disk encryption endpoint security policy category provides settings for managing encryption technologies such as BitLocker on supported Windows devices. Administrators can configure encryption requirements and related settings through Intune to help protect data stored on organizational endpoints. Antivirus policies manage malware protection, Firewall policies control network traffic, and Account protection focuses on account and authentication security. Disk encryption is therefore the appropriate policy category when administrators need to configure BitLocker across managed Windows devices. Centralized policy management also helps maintain consistent encryption requirements throughout the organization.
Question 286
Which Windows Autopilot capability allows a technician to prepare a device before it is delivered to the end user?
- Self-deploying mode
- User-driven mode
- Pre-provisioning
- Autopilot Reset
Correct Answer: 3
Explanation
Windows Autopilot pre-provisioning allows a technician, partner, or deployment team to prepare a device before the end user receives it. During this process, required applications, policies, and organizational configurations can be applied so the user’s setup experience is reduced. Self-deploying mode is designed for deployments that do not require user authentication during initial provisioning, while user-driven mode requires user participation. Autopilot Reset prepares an already deployed device for reuse. Pre-provisioning is therefore the appropriate capability when a technician must prepare the endpoint before handing it to the user.
Question 287
Which Intune capability provides administrators with recommended security configurations that can be deployed as a standardized policy?
- Security baseline
- App configuration policy
- Device category
- Device cleanup rule
Correct Answer: 1
Explanation
Security baselines provide predefined collections of recommended security settings for supported Windows devices. Administrators can review the baseline, determine whether the settings meet organizational requirements, customize supported options, and assign the policy to appropriate users or devices. This helps establish a consistent security posture without manually creating every security configuration from scratch. App configuration policies manage application settings, device categories classify endpoints, and device cleanup rules manage stale device records. Security baseline is therefore the appropriate Intune capability when administrators want standardized recommended security configurations.
Question 288
Which Microsoft Intune feature allows administrators to remotely force a managed device to check for new policies and applications?
- Retire
- Sync
- Wipe
- Remote lock
Correct Answer: 2
Explanation
The Sync action forces a managed device to contact the Intune service and check for available policy, configuration, and application updates. Administrators commonly use this action during troubleshooting when a recently assigned policy or application has not yet appeared on the endpoint. Retire removes organizational management and supported corporate data, Wipe resets the device according to the selected options, and Remote lock restricts device access. Sync is therefore the appropriate action when administrators need to trigger a management check-in and request the latest assigned configurations.
Question 289
Which Intune capability allows administrators to automatically target devices according to attributes such as operating system or manufacturer?
- Scope tags
- Dynamic device groups
- Device cleanup rules
- Remote Help
Correct Answer: 2
Explanation
Dynamic device groups in Microsoft Entra can automatically include devices according to defined membership rules and device attributes. Organizations can use these groups to target Intune applications, configuration profiles, compliance policies, and other management resources without manually maintaining every membership change. Scope tags control administrative visibility, device cleanup rules manage stale records, and Remote Help provides remote assistance. Dynamic device groups are therefore appropriate when administrators need automatic group membership based on device characteristics such as operating system, manufacturer, or other supported attributes.
Question 290
Which Intune assignment type automatically installs an application on targeted devices or for targeted users?
- Available
- Uninstall
- Required
- Dependency
Correct Answer: 3
Explanation
A Required assignment instructs Intune to deploy an application automatically to the targeted users or devices. This assignment type is useful for mandatory business applications, security software, and other software that the organization expects managed endpoints to have installed. Available assignments allow users to choose installation through Company Portal, Uninstall assignments remove applications, and dependencies establish prerequisite relationships. Required is therefore the correct assignment type when the application should be installed automatically without requiring the user to initiate the installation manually.
Question 291
Which Intune feature provides a user-facing portal where employees can install applications that have been assigned as Available?
- Company Portal
- Settings Catalog
- Endpoint analytics
- Security baseline
Correct Answer: 1
Explanation
Company Portal provides users with a central interface for accessing applications that administrators have assigned as Available. Users can browse supported applications and initiate installations according to organizational policies. Company Portal can also provide supported device management and information features depending on the platform and configuration. Settings Catalog is an administrator-focused configuration tool, Endpoint analytics provides performance and experience insights, and security baselines provide recommended security settings. Company Portal is therefore the appropriate user-facing interface when employees need to install optional applications made available through Intune.
Question 292
Which Intune capability can evaluate whether a managed Windows device has an enabled firewall before determining its compliance state?
- App configuration policy
- Compliance policy
- Device category
- Assignment filter
Correct Answer: 2
Explanation
Compliance policies can evaluate supported device security conditions and determine whether managed endpoints satisfy organizational requirements. A compliance policy can include firewall-related requirements where supported, allowing the organization to mark devices compliant or noncompliant according to configured conditions. The compliance result can also be used with Conditional Access to control access to protected resources. App configuration policies manage application settings, device categories classify devices, and assignment filters refine targeting. Compliance policy is therefore the appropriate capability for evaluating whether a device meets a required firewall security condition.
Question 293
Which Windows security feature helps prevent malicious applications from modifying files stored in protected folders?
- SmartScreen
- BitLocker
- Controlled folder access
- Windows LAPS
Correct Answer: 3
Explanation
Controlled folder access is a Microsoft Defender Antivirus feature that helps protect designated folders from unauthorized changes by potentially malicious applications. It can help reduce the impact of ransomware and other threats that attempt to modify or encrypt important files. Administrators can configure supported Controlled folder access settings through Intune endpoint security policies. SmartScreen provides reputation-based protection, BitLocker encrypts stored data, and Windows LAPS manages local administrator passwords. Controlled folder access is therefore the appropriate feature when the objective is to prevent unauthorized applications from modifying protected files.
Question 294
Which Intune feature allows administrators to define a minimum Windows operating system version for a Win32 application deployment?
- Detection rule
- Dependency
- Supersedence
- Requirement rule
Correct Answer: 4
Explanation
Requirement rules specify conditions that a device must meet before a Win32 application can be installed. One supported requirement can be the minimum Windows operating system version, ensuring that the application is deployed only to compatible endpoints. Detection rules determine whether the application is already installed, dependencies identify prerequisite applications, and supersedence manages replacement of older applications. Requirement rule is therefore the appropriate feature when an administrator needs to restrict application installation based on the Windows operating system version running on the device.
Question 295
Which Microsoft Intune capability helps administrators manage local administrator passwords by automatically rotating them on supported Windows devices?
- Windows LAPS
- Credential Guard
- SmartScreen
- BitLocker
Correct Answer: 1
Explanation
Windows LAPS provides centralized management of local administrator account passwords on supported Windows devices. It can generate and rotate passwords according to organizational policy, reducing risks associated with static or shared local administrator credentials. Intune can be used to configure Windows LAPS settings and deploy them to managed endpoints. Credential Guard protects sensitive authentication information, SmartScreen provides reputation-based protection, and BitLocker protects stored data through encryption. Windows LAPS is therefore the appropriate technology when administrators need automated management and rotation of local administrator passwords.
Question 296
Which Intune capability provides insights into Windows startup performance and other factors affecting the user experience?
- Device inventory
- Endpoint analytics
- Device cleanup
- Enrollment restrictions
Correct Answer: 2
Explanation
Endpoint analytics provides organizations with information about Windows device performance and user experience. It can help administrators identify areas such as startup performance, application reliability, and other endpoint conditions that may affect productivity. These insights can support troubleshooting and help IT teams determine where improvements may be needed. Device inventory provides hardware and software information, device cleanup manages stale records, and enrollment restrictions control which devices can enter Intune management. Endpoint analytics is therefore the appropriate capability for analyzing endpoint performance and user experience.
Question 297
Which Intune feature can protect corporate information inside supported applications by restricting actions such as copying data to unmanaged applications?
- App protection policy
- Security baseline
- Update ring
- Device cleanup rule
Correct Answer: 1
Explanation
App protection policies help protect organizational information within supported applications by controlling how corporate data can be accessed, transferred, copied, or saved. They are particularly useful for mobile application management scenarios where users may access company resources from personally owned devices. Administrators can configure data transfer restrictions and other controls without necessarily requiring full device enrollment. Security baselines configure Windows security settings, update rings manage Windows Update behavior, and device cleanup rules manage stale records. App protection policy is therefore the appropriate capability for protecting corporate data within supported applications.
Question 298
Which Intune capability can automatically replace an older Win32 application with a newer version?
- Detection rule
- Requirement rule
- Dependency
- Supersedence
Correct Answer: 4
Explanation
Supersedence allows administrators to define relationships in which a newer Win32 application replaces an older application or version. This capability supports application lifecycle management by helping organizations move users from outdated software to newer approved releases. Detection rules determine whether an application is installed, requirement rules determine whether a device meets installation conditions, and dependencies identify prerequisite applications. Supersedence is therefore the appropriate Intune capability when administrators need to replace an existing Win32 application with a newer deployment in a controlled manner.
Question 299
Which Microsoft Entra capability can be used with Intune to require compliant devices before users access organizational resources?
- Dynamic groups
- Conditional Access
- Device registration
- Scope tags
Correct Answer: 2
Explanation
Microsoft Entra Conditional Access can use Intune compliance status as a condition when evaluating access requests. An organization can configure a policy requiring users to access selected resources only from devices that meet defined compliance requirements. If the device is noncompliant, the configured Conditional Access policy can block or otherwise restrict access. Dynamic groups manage automatic membership, device registration establishes a device identity, and scope tags control Intune administrative visibility. Conditional Access is therefore the appropriate capability for enforcing access requirements based on device compliance.
Question 300
Which Intune device action removes organizational management and corporate data while generally preserving personal user information?
- Wipe
- Restart
- Retire
- Sync
Correct Answer: 3
Explanation
The Retire action removes organizational management and supported corporate data from a device while generally preserving personal user information. It is particularly useful for personally owned devices when an employee no longer needs access to organizational resources or when corporate management should be removed without intentionally erasing personal content. Wipe performs a broader reset and can remove device data, Restart simply reboots the device, and Sync initiates a management check-in. Retire is therefore the appropriate action when organizational data and management need to be removed while personal information is generally preserved.