{"id":14345,"date":"2026-09-17T04:41:02","date_gmt":"2026-09-17T04:41:02","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=14345"},"modified":"2026-09-17T04:41:02","modified_gmt":"2026-09-17T04:41:02","slug":"microsoft-md-102-practice-test-questions-and-exam-dumps-part11-q201-220","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/microsoft-md-102-practice-test-questions-and-exam-dumps-part11-q201-220\/","title":{"rendered":"Microsoft MD-102 Practice Test Questions and Exam Dumps Part11 Q201-220"},"content":{"rendered":"<h1><\/h1>\n<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/md-102-exam-dumps\"><b>Microsoft MD-102 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 201<\/b><\/h3>\n<p><b>Which Microsoft Intune feature allows administrators to configure recommended security settings across managed Windows devices?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security baseline<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Device category<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Company Portal<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Enrollment restriction<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Security baselines in Microsoft Intune provide predefined groups of recommended security settings that administrators can deploy to supported Windows devices. They help organizations establish a consistent security configuration without manually configuring every individual security setting. Administrators can review the baseline settings, customize them when necessary, and assign the resulting policy to appropriate users or devices. Device categories are used for organization and targeting, Company Portal provides user-facing functionality, and enrollment restrictions control device enrollment. Security baselines are therefore the appropriate choice for applying standardized recommended security configurations.<\/span><\/p>\n<h3><b>Question 202<\/b><\/h3>\n<p><b>Which Microsoft Entra device identity represents a device that is registered primarily for personal or bring-your-own-device scenarios?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra joined<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra registered<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra hybrid joined<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Configuration Manager enrolled<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra registered devices are commonly associated with personal or bring-your-own-device scenarios where users access organizational resources without fully joining the device to the organization&#8217;s Microsoft Entra environment. Registration establishes a device identity that can be used with supported identity and access controls. Microsoft Entra joined devices are generally fully joined to the organization&#8217;s cloud identity environment, while hybrid joined devices combine on-premises Active Directory membership with Microsoft Entra registration. Configuration Manager enrollment describes management rather than the Microsoft Entra device identity itself. Microsoft Entra registered is therefore correct.<\/span><\/p>\n<h3><b>Question 203<\/b><\/h3>\n<p><b>An organization wants to automatically place newly enrolled devices into groups based on device attributes. Which Microsoft Entra capability should administrators use?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Static security group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Device category<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Dynamic device group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Scope tag<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Dynamic device groups in Microsoft Entra can automatically include or exclude devices based on defined membership rules and device attributes. When a device&#8217;s relevant attributes change, group membership can be updated according to the configured rule. This is useful for automatically targeting Intune policies, applications, and compliance configurations without manually maintaining membership. Static groups require administrators to manage membership manually, device categories provide classification information, and scope tags control administrative visibility. Dynamic device groups are therefore appropriate when devices should automatically become members based on their properties.<\/span><\/p>\n<h3><b>Question 204<\/b><\/h3>\n<p><b>Which Intune enrollment method is designed to allow an organization to enroll and manage a large number of devices using a designated enrollment account?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Windows Autopilot<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Device Enrollment Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Automatic MDM enrollment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra registration<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Device Enrollment Manager, or DEM, is an Intune capability that allows a designated account to enroll and manage multiple devices. It is useful in scenarios such as shared devices, frontline environments, or deployments where many endpoints must be enrolled without assigning each enrollment operation to a separate standard user. DEM accounts have specific limitations and permissions that administrators should consider before using them. Windows Autopilot is primarily designed for provisioning devices, automatic MDM enrollment relies on user enrollment conditions, and Microsoft Entra registration establishes device identity. DEM is therefore the appropriate choice.<\/span><\/p>\n<h3><b>Question 205<\/b><\/h3>\n<p><b>Which Windows Autopilot deployment mode is designed to provision a device without requiring the user to enter credentials during the initial deployment?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">User-driven mode<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Pre-provisioning<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Self-deploying mode<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hybrid join deployment<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Windows Autopilot self-deploying mode is designed for scenarios where a device should be provisioned with organizational configuration without requiring a user to authenticate during the initial deployment process. It is useful for shared devices, kiosks, and other scenarios where the device is prepared before being assigned to an individual user. User-driven mode requires user interaction and authentication, while pre-provisioning allows technicians or partners to prepare devices before users receive them. Hybrid join refers to the identity configuration. Self-deploying mode is therefore the correct choice for this scenario.<\/span><\/p>\n<h3><b>Question 206<\/b><\/h3>\n<p><b>Which Intune feature can configure a Windows device to automatically remove temporary files and reclaim disk space?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Storage Sense configuration<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security baseline<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Compliance policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Endpoint analytics<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Storage Sense is a Windows capability that can automatically manage storage by removing unnecessary temporary files and other supported items. Intune can be used to configure Storage Sense settings on managed Windows devices through appropriate configuration policies. This helps organizations maintain available disk space without requiring users to manually perform cleanup operations. Security baselines focus on recommended security settings, compliance policies evaluate whether devices satisfy requirements, and Endpoint analytics provides performance insights. Storage Sense configuration is therefore the appropriate option when administrators need automated management of temporary files and storage usage.<\/span><\/p>\n<h3><b>Question 207<\/b><\/h3>\n<p><b>An administrator needs to configure Microsoft Edge settings for managed Windows devices using Intune. Which policy type is appropriate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Compliance policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Administrative templates<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Device cleanup rule<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Remote Help policy<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Administrative templates in Intune provide policy settings that administrators can use to configure applications and Windows behavior. They are commonly used to manage Microsoft Edge settings across organizational devices, including supported browser configurations and user experience controls. Compliance policies evaluate device conditions rather than primarily configuring Edge settings. Device cleanup rules remove stale device records, while Remote Help supports remote assistance. Administrative templates are therefore an appropriate Intune policy type when an organization needs centralized configuration of supported Microsoft Edge settings across managed Windows devices.<\/span><\/p>\n<h3><b>Question 208<\/b><\/h3>\n<p><b>Which Intune action is most appropriate when a corporate Windows device must be completely reset and its existing data removed before reassignment?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Sync<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Restart<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Wipe<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Remote lock<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Wipe action is designed to reset a device and remove its data according to the selected wipe behavior. It is useful when a corporate device is being retired, repurposed, or reassigned and existing organizational or user data should not remain accessible. Sync only forces the device to check in with Intune, Restart reboots the device, and Remote lock prevents access until the device is unlocked. Administrators should carefully select wipe options because the action can remove data from the device. Wipe is therefore appropriate for a complete reset before reassignment.<\/span><\/p>\n<h3><b>Question 209<\/b><\/h3>\n<p><b>Which Microsoft Intune capability can help administrators identify devices that have not checked in recently so that stale records can be removed?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Device cleanup rules<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security baselines<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">App protection policies<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Settings Catalog<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Device cleanup rules can help organizations identify and remove stale Intune device records based on the configured period since the device last checked in. This helps maintain a cleaner device inventory and reduces confusion caused by outdated records. Administrators should configure cleanup rules carefully because removing an Intune record does not necessarily mean the physical device itself has been erased. Security baselines configure security settings, app protection policies protect organizational data within supported applications, and Settings Catalog configures device settings. Device cleanup rules are therefore the correct capability for stale records.<\/span><\/p>\n<h3><b>Question 210<\/b><\/h3>\n<p><b>Which Intune feature allows an administrator to configure settings using custom OMA-URI values when a required setting is not available through standard policy interfaces?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security baseline<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Compliance policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Custom configuration profile<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Update ring<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Custom configuration profiles can use OMA-URI settings to configure supported Windows management settings that may not be exposed through standard Intune policy interfaces. Administrators specify the appropriate OMA-URI path, data type, and value to deliver the desired configuration through mobile device management. This approach requires accurate knowledge of the supported configuration settings because incorrect values or paths can cause policy failures. Security baselines provide predefined security configurations, compliance policies evaluate device state, and update rings manage Windows Update behavior. A custom configuration profile is therefore the appropriate choice.<\/span><\/p>\n<h3><b>Question 211<\/b><\/h3>\n<p><b>Which Intune application assignment type automatically installs an application on targeted devices without requiring users to initiate the installation?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Available<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Required<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Uninstall<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Optional<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Required application assignment instructs Intune to deploy the application automatically to targeted users or devices. Depending on the application and configuration, the installation can occur without the user manually selecting the application in Company Portal. This assignment type is useful for mandatory business applications, security software, and other software that the organization expects endpoints to have. Available assignments allow users to initiate installation, while Uninstall assignments remove applications. Required is therefore the appropriate assignment type when the application must be automatically installed on targeted endpoints.<\/span><\/p>\n<h3><b>Question 212<\/b><\/h3>\n<p><b>Which Microsoft Intune capability allows administrators to provide remote assistance to users on supported managed devices?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Endpoint analytics<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Remote Help<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Device query<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Windows Autopilot<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Remote Help is an Intune capability designed to provide secure remote assistance for supported managed devices. It allows authorized support personnel to connect to users&#8217; devices and assist with troubleshooting while applying organizational access controls. This can help support teams resolve endpoint issues without requiring physical access to the device. Endpoint analytics provides performance and experience insights, Device query retrieves supported device information, and Windows Autopilot handles provisioning and deployment. Remote Help is therefore the appropriate capability when administrators or support staff need to assist users remotely.<\/span><\/p>\n<h3><b>Question 213<\/b><\/h3>\n<p><b>Which Intune policy can determine whether a device has antivirus protection enabled before allowing access through Conditional Access?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Configuration profile<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Compliance policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Update ring<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A compliance policy can evaluate whether a managed device satisfies required security conditions, including supported antivirus requirements. The resulting compliance state can then be used by Microsoft Entra Conditional Access to restrict access to organizational resources when a device fails the required conditions. Configuration profiles primarily configure settings, application policies manage software behavior or deployment, and update rings manage Windows Update settings. Compliance policies therefore provide the evaluation layer needed to determine whether the device meets the organization&#8217;s security requirements before Conditional Access makes an access decision.<\/span><\/p>\n<h3><b>Question 214<\/b><\/h3>\n<p><b>Which Microsoft Intune feature is used to configure local administrator account protection settings on supported Windows devices?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Account protection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disk encryption<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Antivirus<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Firewall<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Account protection endpoint security policy category in Intune provides settings related to account security and supported Windows authentication protections. It can be used to configure appropriate controls around local accounts and Windows security features, depending on the device and policy configuration. Disk encryption focuses on technologies such as BitLocker, antivirus policies configure malware protection, and firewall policies manage network traffic controls. When an administrator needs to configure supported account-related security settings through Intune endpoint security, Account protection is the relevant policy category.<\/span><\/p>\n<h3><b>Question 215<\/b><\/h3>\n<p><b>An administrator wants to prevent users from installing applications from unauthorized sources on managed Windows devices. Which security capability can help enforce application control?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Delivery Optimization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">App Control for Business<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Storage Sense<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Endpoint analytics<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">App Control for Business helps organizations control which applications are permitted to run on managed Windows devices. Administrators can establish policies that allow trusted applications while restricting unauthorized or unapproved software. This supports application control and can reduce the risk associated with unknown or malicious programs. Delivery Optimization manages content delivery, Storage Sense manages disk space, and Endpoint analytics provides endpoint performance insights. App Control for Business is therefore the relevant security capability when an organization wants to enforce application execution controls on supported Windows endpoints.<\/span><\/p>\n<h3><b>Question 216<\/b><\/h3>\n<p><b>Which Windows feature provides hardware-based protection that can help establish trust during the device startup process?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Storage Sense<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">TPM<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Event Viewer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Task Manager<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Trusted Platform Module, or TPM, is a hardware-based security component that can securely store cryptographic information and support platform integrity features. Windows security technologies can use TPM capabilities for operations such as device authentication, BitLocker protection, and Windows Hello for Business. Storage Sense manages disk space, Event Viewer provides system and application logs, and Task Manager displays running processes and resource usage. TPM is therefore the appropriate choice when the requirement involves hardware-based security and establishing trust during supported Windows security operations.<\/span><\/p>\n<h3><b>Question 217<\/b><\/h3>\n<p><b>Which Intune capability allows administrators to collect and examine endpoint information by running supported queries against managed Windows devices?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Device query<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Device cleanup<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Company Portal<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Enrollment Status Page<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Device query enables administrators to retrieve specific information from supported managed Windows devices by using queries. This capability can assist with troubleshooting, inventory investigations, security analysis, and operational tasks. Instead of manually checking each endpoint, administrators can query relevant device information centrally and use the results to identify conditions that require attention. Device cleanup is used to manage stale records, Company Portal is primarily user-facing, and Enrollment Status Page monitors provisioning during enrollment. Device query is therefore the appropriate capability for retrieving endpoint information through supported queries.<\/span><\/p>\n<h3><b>Question 218<\/b><\/h3>\n<p><b>Which Windows Autopilot capability allows an organization to prepare a device before handing it over to the end user?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Self-deploying mode<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Pre-provisioning<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Device cleanup<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Remote lock<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Windows Autopilot pre-provisioning allows an authorized technician, partner, or deployment team to prepare a device before it reaches the end user. During pre-provisioning, required applications, policies, and organizational configurations can be applied so that the user&#8217;s initial setup experience is reduced. Self-deploying mode is designed for deployments that do not require user authentication during provisioning, while device cleanup manages stale Intune records and Remote lock restricts access to a device. Pre-provisioning is therefore the appropriate Autopilot capability for preparing devices before user handoff.<\/span><\/p>\n<h3><b>Question 219<\/b><\/h3>\n<p><b>Which Intune capability helps ensure that a device automatically receives organizational configuration after it enrolls?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Device category<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Scope tag<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Policy assignment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hardware inventory<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Policy assignments determine which users or devices receive Intune configurations, compliance policies, applications, and other management policies. Administrators can assign policies directly to groups and use supported filters or assignment conditions to refine the targeting. Once a device enrolls and meets the assignment criteria, it can receive the applicable organizational configuration. Device categories classify devices, scope tags control administrative visibility, and hardware inventory provides information about device characteristics. Policy assignment is therefore the key mechanism for ensuring that enrolled devices receive the configurations intended for their assigned users or groups.<\/span><\/p>\n<h3><b>Question 220<\/b><\/h3>\n<p><b>Which Microsoft Entra feature can require a device to be compliant before a user is permitted to access protected organizational resources?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra registration<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Conditional Access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Dynamic device groups<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Device categories<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra Conditional Access can use device compliance as a condition when making access decisions. An organization can configure a policy requiring users to access protected resources only from devices that meet defined Intune compliance requirements. If the device is marked noncompliant, the Conditional Access policy can block or otherwise restrict access according to its configuration. Microsoft Entra registration establishes a device identity, dynamic device groups manage automatic group membership, and device categories provide classification. Conditional Access is therefore the appropriate feature for enforcing access requirements based on device compliance.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Microsoft MD-102 Exam Dumps and Practice Test Dumps. &nbsp; Question 201 Which Microsoft Intune feature allows administrators to configure recommended security settings across managed Windows devices? Security baseline Device category Company Portal Enrollment restriction Correct Answer: 1 Explanation Security baselines in Microsoft Intune provide predefined groups of recommended security settings that administrators can [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14345"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=14345"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14345\/revisions"}],"predecessor-version":[{"id":14366,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14345\/revisions\/14366"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=14345"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=14345"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=14345"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}