View Full Microsoft MD-102 Exam Dumps and Practice Test Dumps.
Question 81
Which Intune feature allows administrators to configure recommended security settings for managed Windows devices based on Microsoft’s security guidance?
- Security baseline
- Device category
- Enrollment restriction
- Application assignment
Correct Answer: 1
Explanation
An Intune security baseline provides a collection of recommended security configuration settings based on Microsoft’s security guidance. Administrators can deploy these settings to Windows devices and adjust them according to organizational requirements. Security baselines can help standardize important protections across managed endpoints and reduce the need to configure every security setting individually. They may include settings related to authentication, Microsoft Defender, firewall, and other Windows security capabilities. Security baselines differ from compliance policies, which evaluate whether devices meet specified requirements rather than primarily configuring security settings.
Question 82
An administrator needs to ensure that only devices running an approved minimum Windows version can access company resources. Which Intune capability should be configured?
- Device cleanup rule
- Compliance policy
- Application configuration policy
- Scope tag
Correct Answer: 2
Explanation
An Intune compliance policy can require devices to run an approved minimum operating system version. Administrators define the acceptable Windows version and can configure the device as noncompliant when it does not meet that requirement. Compliance can then be combined with Conditional Access to restrict access to organizational resources from devices that fail the required conditions. Device cleanup rules remove stale device records, while application configuration policies manage application settings. Scope tags control administrative visibility and do not evaluate operating system versions.
Question 83
Which Windows Autopilot deployment option is designed primarily for organizations that want users to complete the device setup themselves?
- Self-deploying mode
- Pre-provisioning
- User-driven mode
- Autopilot Reset
Correct Answer: 3
Explanation
Windows Autopilot user-driven mode is designed for scenarios where the end user completes the device setup process. During deployment, the user signs in with organizational credentials and the device receives its assigned configuration, applications, and policies. This approach is useful for standard employee devices that are shipped directly to users without requiring extensive technician involvement. Pre-provisioning allows IT staff or partners to prepare devices before delivery. Self-deploying mode is intended for scenarios where user interaction should be minimized, while Autopilot Reset prepares an existing device for reuse.
Question 84
Which Intune action requests a managed device to immediately check in and retrieve the latest policies?
- Restart
- Sync
- Wipe
- Retire
Correct Answer: 2
Explanation
The Sync action in Intune requests a managed device to check in with the Intune service and retrieve available policies, applications, and configuration changes. Administrators commonly use this action when troubleshooting policy deployment or when a device has not yet received a recent configuration change. Restart simply reboots the device, while Wipe removes device data according to the selected reset options. Retire removes organizational management and corporate data while generally preserving personal information. Sync is therefore the appropriate action when an administrator wants the device to check for updated management instructions.
Question 85
Which Intune policy type is used to configure settings such as password complexity, account lockout, and Windows Hello for Business?
- Account protection policy
- Device cleanup policy
- Update ring
- Application protection policy
Correct Answer: 1
Explanation
An Intune endpoint security account protection policy can manage identity and authentication-related security settings on supported Windows devices. Depending on the available settings, administrators can configure protections involving Windows Hello for Business, account security, and related authentication controls. These policies help organizations establish consistent identity protection across managed endpoints. Device cleanup policies address stale device records, while update rings manage Windows Update behavior. Application protection policies focus on protecting organizational data inside supported applications. Account protection is therefore the relevant endpoint security policy category for authentication and account-related configurations.
Question 86
A company wants users to access corporate applications from personal mobile devices without enrolling the entire device in Intune. Which capability should be used?
- Device compliance
- Mobile device enrollment
- Mobile application management with app protection policies
- Windows Autopilot
Correct Answer: 3
Explanation
Mobile application management combined with Intune app protection policies allows organizations to protect corporate data inside supported applications without requiring full device enrollment in many BYOD scenarios. Policies can control actions such as copying organizational data, saving information to personal locations, and requiring application-level access controls. This approach is useful when an organization wants to protect business data while allowing employees to use personal devices. Device compliance evaluates managed device conditions, mobile enrollment manages the entire device, and Windows Autopilot is intended for Windows provisioning.
Question 87
Which Intune feature allows administrators to configure Microsoft 365 Apps for enterprise on managed Windows devices?
- Microsoft 365 Apps deployment
- Device cleanup
- Security baseline
- Windows Autopilot Reset
Correct Answer: 1
Explanation
Microsoft Intune includes application management capabilities for deploying Microsoft 365 Apps for enterprise to managed Windows devices. Administrators can configure application settings such as the Office applications to install, update channel, architecture, language, and other deployment options. The deployment can then be assigned to appropriate users or device groups. Security baselines configure security settings rather than Office installation. Device cleanup removes stale device records, while Autopilot Reset prepares a Windows device for reuse. Microsoft 365 Apps deployment is therefore the appropriate Intune capability for managing Office installation.
Question 88
An administrator wants to configure Microsoft Edge settings across all managed Windows devices from a centralized location. Which Intune capability is appropriate?
- Compliance actions
- Microsoft Edge configuration policies
- Device wipe
- Enrollment restrictions
Correct Answer: 2
Explanation
Microsoft Edge configuration policies in Intune allow administrators to centrally manage supported browser settings on organizational Windows devices. These policies can control browser behavior, security-related options, extensions, updates, and other supported Edge settings. Centralized configuration helps maintain consistent browser settings across managed endpoints. Compliance actions are used when devices fail compliance requirements, while device wipe removes device data. Enrollment restrictions control which devices can enroll in Intune. Therefore, Edge configuration policies provide the appropriate method for centrally managing Microsoft Edge settings.
Question 89
Which Windows feature allows users to recover deleted or modified files by using previous versions stored through supported protection mechanisms?
- Storage Sense
- Delivery Optimization
- File History
- Task Scheduler
Correct Answer: 3
Explanation
File History is a Windows feature that can automatically back up selected personal files to another storage location, allowing users to restore previous versions of files when needed. It can help recover files that were accidentally modified or deleted, provided the required backup history exists. Storage Sense is designed to free disk space by managing temporary and unnecessary files. Delivery Optimization helps distribute Windows updates efficiently, while Task Scheduler runs automated tasks according to defined triggers. File History is therefore the relevant feature for restoring previous versions of supported personal files.
Question 90
An organization wants to enforce multifactor authentication only when users access resources from devices that do not meet its security requirements. Which combination should be used?
- Storage Sense and Update rings
- Device categories and scope tags
- App configuration and Win32 detection
- Conditional Access and device compliance
Correct Answer: 4
Explanation
Conditional Access can use device compliance as a condition when deciding whether users should be granted access to organizational resources. An organization can configure compliance policies that define security requirements and then use Conditional Access to apply additional controls when a device does not satisfy those requirements. Depending on the policy design, users may be required to complete multifactor authentication or may be blocked from access. Storage Sense, update rings, device categories, and application settings do not provide this identity-and-device access control combination.
Question 91
Which Intune feature is specifically designed to manage local administrator passwords on Windows devices?
- Windows LAPS
- Delivery Optimization
- Storage Sense
- Microsoft Store
Correct Answer: 1
Explanation
Windows LAPS, or Windows Local Administrator Password Solution, helps organizations manage and protect local administrator account passwords on supported Windows devices. Intune can be used to configure Windows LAPS policies and manage related settings for enrolled devices. Passwords can be rotated according to organizational requirements, reducing the risks associated with using the same local administrator password across multiple devices. Delivery Optimization manages content delivery, Storage Sense manages disk space, and Microsoft Store provides application distribution. Windows LAPS is specifically designed for local administrator password management.
Question 92
Which Intune capability provides a centralized catalog where enrolled users can find and install applications assigned as available?
- Settings Catalog
- Company Portal
- Endpoint analytics
- Security baseline
Correct Answer: 2
Explanation
Company Portal provides users with a centralized interface for accessing applications that have been made available to them through Intune. Users can browse supported applications and initiate installations without requiring administrators to manually install each optional application. Company Portal can also provide device-related actions and organizational information depending on the platform and configuration. Settings Catalog is used by administrators to configure device settings, while Endpoint analytics provides performance and user-experience insights. Security baselines provide recommended security configurations rather than acting as an application catalog.
Question 93
Which Intune capability can automatically remove devices from management records when they have not checked in for a defined period?
- Device cleanup rules
- Conditional Access
- Security baselines
- App protection policies
Correct Answer: 1
Explanation
Device cleanup rules in Intune help organizations manage stale device records by automatically removing devices that have not checked in for a configured period. This can reduce clutter in the Intune admin center and make device inventory easier to manage. The cleanup process does not necessarily remove the device itself from existence; rather, it helps maintain the administrative records. Conditional Access controls access to resources, security baselines configure recommended security settings, and app protection policies protect organizational data within applications. Device cleanup rules are therefore appropriate for stale management records.
Question 94
Which Windows management architecture allows an organization to manage devices through both Microsoft Configuration Manager and Intune?
- Windows Autopilot
- Co-management
- Windows Hello for Business
- Windows Sandbox
Correct Answer: 2
Explanation
Co-management allows supported Windows devices to be managed by both Microsoft Configuration Manager and Microsoft Intune. Organizations can gradually transition management workloads from Configuration Manager to cloud-based management while maintaining existing capabilities where necessary. Different workloads can be assigned to either management platform according to organizational requirements. Windows Autopilot focuses on provisioning and deployment, Windows Hello for Business provides authentication capabilities, and Windows Sandbox provides an isolated environment for testing. Co-management specifically addresses the combined management of Windows devices through Configuration Manager and Intune.
Question 95
An administrator needs to determine whether a device’s hardware meets Windows 11 requirements before upgrading it. Which Intune capability can help provide device hardware information?
- Device inventory
- Application protection
- App assignment
- Conditional Access
Correct Answer: 1
Explanation
Intune device inventory provides administrators with information about managed devices, including supported hardware and software details. This information can help organizations assess device readiness for operating system upgrades and identify systems that may require replacement or remediation. Hardware-related information can include processor, memory, storage, and other device characteristics depending on the platform and available inventory data. Application protection focuses on application data security, app assignment controls software deployment, and Conditional Access controls resource access. Device inventory is therefore the appropriate capability for reviewing endpoint hardware information.
Question 96
Which Intune policy type is designed to configure disk encryption settings such as BitLocker on managed Windows devices?
- Account protection policy
- Disk encryption policy
- Application configuration policy
- Device cleanup policy
Correct Answer: 2
Explanation
The Intune endpoint security disk encryption policy is designed to configure encryption-related settings for managed Windows devices, including BitLocker. Administrators can use it to establish organizational requirements for operating system drive encryption, recovery settings, and related protections. Centralized encryption management helps protect data if a device is lost or stolen. Account protection policies focus on identity and authentication settings, application configuration policies manage supported application settings, and device cleanup policies handle stale device records. Disk encryption policy is therefore the appropriate choice for configuring BitLocker-related settings through Intune.
Question 97
A user reports that an application assigned as Required has not installed on their Windows device. Which Intune action should the administrator try first to trigger a fresh policy check?
- Retire
- Wipe
- Sync
- Remote lock
Correct Answer: 3
Explanation
The Sync action is a useful first troubleshooting step when a required application or policy has not reached a managed device. It prompts the device to communicate with Intune and check for updated management instructions. After synchronization, the device can retrieve newly assigned applications and policies according to its configuration and check-in behavior. Retire removes organizational management, Wipe resets the device, and Remote lock locks the device without initiating a normal policy retrieval process. Sync is therefore the least disruptive and most appropriate initial action for this situation.
Question 98
Which Intune feature allows administrators to create reusable groups of settings through a modern centralized settings interface?
- Settings Catalog
- Device cleanup rules
- Remote Help
- Autopilot Reset
Correct Answer: 1
Explanation
The Intune Settings Catalog provides a centralized interface containing many configurable Windows and other supported device settings. Administrators can search for specific settings, configure values, and deploy the resulting policy to targeted users or devices. It provides a modern alternative to managing many settings through older configuration templates and can simplify policy creation. Device cleanup rules manage stale records, Remote Help supports remote assistance scenarios, and Autopilot Reset prepares devices for reuse. Settings Catalog is therefore the appropriate feature for creating and managing centralized configuration policies from available settings.
Question 99
Which Microsoft Defender capability is designed to detect, investigate, and respond to threats affecting organizational endpoints?
- Microsoft Defender Antivirus
- Microsoft Defender for Endpoint
- Microsoft Defender Firewall
- Microsoft Defender SmartScreen
Correct Answer: 2
Explanation
Microsoft Defender for Endpoint provides endpoint security capabilities focused on detecting, investigating, and responding to threats across organizational devices. It can provide security signals, alerts, investigation capabilities, and response actions that help security teams investigate suspicious activity. Microsoft Defender Antivirus primarily provides malware protection, while Microsoft Defender Firewall controls network traffic. SmartScreen helps protect users from malicious websites, downloads, and applications. Defender for Endpoint is therefore the broader endpoint detection and response platform used to monitor and respond to security threats across managed devices.
Question 100
An organization wants to ensure that a Windows device cannot complete Autopilot deployment until required applications and policies have finished installing. Which feature should be configured?
- Device cleanup rules
- Enrollment Status Page
- Windows LAPS
- App protection policy
Correct Answer: 2
Explanation
The Enrollment Status Page can be configured to control the Windows Autopilot deployment experience and ensure that required applications and policies are processed before the user reaches the Windows desktop. This helps organizations prevent users from starting work on devices that have not yet received critical configurations. Administrators can configure ESP to track device setup and required application installation during deployment. Device cleanup rules manage stale records, Windows LAPS manages local administrator passwords, and app protection policies protect organizational data inside supported applications. ESP is therefore the appropriate feature for this deployment requirement.