{"id":14353,"date":"2026-09-17T04:40:06","date_gmt":"2026-09-17T04:40:06","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=14353"},"modified":"2026-09-17T04:40:06","modified_gmt":"2026-09-17T04:40:06","slug":"microsoft-md-102-practice-test-questions-and-exam-dumps-part18-q341-360","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/microsoft-md-102-practice-test-questions-and-exam-dumps-part18-q341-360\/","title":{"rendered":"Microsoft MD-102 Practice Test Questions and Exam Dumps Part18 Q341-360"},"content":{"rendered":"<h1><\/h1>\n<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/md-102-exam-dumps\"><b>Microsoft MD-102 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 341<\/b><\/h3>\n<p><b>Which Intune feature allows administrators to define a grace period before a device is considered noncompliant?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Assignment filter<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security baseline<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Device category<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Compliance policy action<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Compliance policy actions can define what happens when a device does not meet compliance requirements, including configuring a grace period before the device is treated as noncompliant. This gives users an opportunity to correct an issue before stronger enforcement occurs. Assignment filters control policy targeting, security baselines configure recommended security settings, and device categories classify managed devices. Compliance policy actions are therefore the appropriate feature when administrators want to provide users with a defined period to remediate a compliance issue before enforcement takes effect.<\/span><\/p>\n<h3><b>Question 342<\/b><\/h3>\n<p><b>Which Microsoft Intune enrollment method automatically enrolls supported Windows devices into MDM when a user signs in with an organizational account?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Automatic MDM enrollment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Device cleanup<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Remote Help<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Windows Sandbox<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Automatic MDM enrollment allows supported Windows devices to automatically enroll into mobile device management when users sign in with organizational credentials, provided the required Microsoft Entra and Intune configuration is in place. This reduces manual enrollment steps and helps organizations automatically bring eligible devices under management. Device cleanup removes stale records, Remote Help provides remote assistance, and Windows Sandbox provides an isolated testing environment. Automatic MDM enrollment is therefore the appropriate feature when organizations want eligible Windows devices to enter Intune management automatically after user authentication.<\/span><\/p>\n<h3><b>Question 343<\/b><\/h3>\n<p><b>Which Intune feature allows administrators to manage Windows devices that are connected to both Configuration Manager and Intune?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Windows Autopilot<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Co-management<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Company Portal<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Windows LAPS<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Co-management allows organizations to manage Windows devices using both Microsoft Configuration Manager and Microsoft Intune. This provides a transition path from traditional on-premises management toward cloud-based endpoint management. Organizations can gradually move supported workloads to Intune while continuing to use Configuration Manager for workloads that have not yet been transferred. Windows Autopilot focuses on provisioning, Company Portal provides user-facing functionality, and Windows LAPS manages local administrator passwords. Co-management is therefore the correct solution when both Configuration Manager and Intune need to manage Windows endpoints.<\/span><\/p>\n<h3><b>Question 344<\/b><\/h3>\n<p><b>Which Intune feature is designed to protect organizational data within supported mobile applications without requiring full device enrollment?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Device configuration profile<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security baseline<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">App protection policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Update ring<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">App protection policies are designed to protect organizational data inside supported applications, particularly in scenarios where full device enrollment may not be required. They can help control actions such as copying organizational data to unsupported applications, saving data to personal locations, and other supported data-transfer behaviors. Device configuration profiles configure device settings, security baselines provide predefined security configurations, and update rings manage Windows Update behavior. App protection policy is therefore the appropriate Intune feature when the organization needs application-level data protection without necessarily requiring full device management.<\/span><\/p>\n<h3><b>Question 345<\/b><\/h3>\n<p><b>Which Microsoft Entra authentication method provides passwordless sign-in using a device-bound credential and supported biometric or PIN verification?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Windows Hello for Business<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">BitLocker<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SmartScreen<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Storage Sense<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Windows Hello for Business provides passwordless authentication using a device-bound credential protected by the Windows device. Users can authenticate using supported methods such as a PIN or biometric verification, depending on device capabilities and organizational configuration. This approach reduces reliance on traditional passwords while providing strong authentication. BitLocker protects stored data through encryption, SmartScreen provides reputation-based protection, and Storage Sense manages disk space. Windows Hello for Business is therefore the appropriate authentication technology for passwordless sign-in using a device-bound credential.<\/span><\/p>\n<h3><b>Question 346<\/b><\/h3>\n<p><b>Which Windows security feature helps prevent unauthorized applications from executing by allowing administrators to define application control policies?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Storage Sense<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">File History<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">App Control for Business<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Remote Desktop<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">App Control for Business provides application control capabilities that allow organizations to manage which applications are permitted to run on Windows devices. Administrators can establish policies that restrict unauthorized or untrusted applications, helping reduce the attack surface of managed endpoints. Storage Sense manages storage space, File History provides file backup capabilities, and Remote Desktop enables remote interactive access. App Control for Business is therefore the appropriate security feature when administrators need centralized control over which applications can execute on organizational Windows devices.<\/span><\/p>\n<h3><b>Question 347<\/b><\/h3>\n<p><b>Which Windows Autopilot capability is intended for devices that need provisioning without user interaction during the initial deployment process?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">User-driven mode<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Pre-provisioning<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Company Portal<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Self-deploying mode<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Windows Autopilot self-deploying mode is designed for scenarios where a device should be provisioned without requiring the end user to sign in during the deployment process. It can be useful for shared devices, kiosks, and other specialized endpoints where user interaction is not appropriate during initial provisioning. User-driven mode requires user participation, while pre-provisioning allows a technician to prepare a device before delivery. Company Portal is an application and resource management interface. Self-deploying mode is therefore the correct Autopilot deployment option for minimal user interaction.<\/span><\/p>\n<h3><b>Question 348<\/b><\/h3>\n<p><b>Which Intune capability can restrict a policy assignment to devices that match a specific device attribute?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Scope tag<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Assignment filter<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Device cleanup rule<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Compliance action<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Assignment filters allow administrators to refine policy and application assignments according to device attributes. For example, an administrator can target or exclude devices based on properties such as operating system, manufacturer, model, or other supported attributes. This provides more precise targeting without requiring changes to Microsoft Entra group membership. Scope tags control which administrative objects administrators can see, device cleanup rules remove stale device records, and compliance actions define responses to compliance states. Assignment filters are therefore the correct capability for attribute-based assignment targeting.<\/span><\/p>\n<h3><b>Question 349<\/b><\/h3>\n<p><b>Which Intune application feature allows a newer application to replace an older application during deployment?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Dependency<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Detection rule<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Supersedence<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Requirement rule<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Supersedence allows administrators to configure a newer application to replace an older application during deployment. This is useful when an organization is moving users from an outdated application version to a newer package or product. Administrators can configure supported supersedence relationships so that Intune understands which application should replace another. Dependencies identify prerequisite applications, detection rules determine installation state, and requirement rules determine whether a device meets installation conditions. Supersedence is therefore the appropriate feature for managing application replacement through Intune.<\/span><\/p>\n<h3><b>Question 350<\/b><\/h3>\n<p><b>Which Windows management tool provides a graphical interface for viewing running processes and resource utilization?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Event Viewer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Services<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Device Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Task Manager<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Task Manager provides a graphical interface for viewing running processes, applications, services, performance information, and resource utilization on Windows devices. Administrators can use it to identify applications consuming excessive CPU, memory, disk, or network resources and to troubleshoot performance issues. Event Viewer focuses on event logs, Services manages Windows services, and Device Manager manages hardware devices and drivers. Task Manager is therefore the correct tool when an administrator needs a quick graphical overview of active processes and system resource consumption.<\/span><\/p>\n<h3><b>Question 351<\/b><\/h3>\n<p><b>Which Intune feature can configure supported Microsoft Edge settings for managed Windows devices?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Edge configuration policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Device cleanup rule<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Compliance action<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Remote Help<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Edge configuration policies in Intune allow administrators to manage supported Microsoft Edge settings across organizational devices. Administrators can configure browser behavior, security-related options, extensions, and other supported settings according to organizational requirements. Device cleanup rules manage stale records, compliance actions define responses to compliance states, and Remote Help provides remote assistance. An Edge configuration policy is therefore the appropriate choice when an organization needs centralized management of Microsoft Edge settings on managed Windows endpoints.<\/span><\/p>\n<h3><b>Question 352<\/b><\/h3>\n<p><b>Which Intune feature allows administrators to assign administrative permissions according to specific job responsibilities?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Role-based access control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Device inventory<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Update ring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Device category<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Role-based access control, or RBAC, allows organizations to delegate Intune administration according to job responsibilities. Administrators can assign predefined roles or create appropriate custom roles and then assign them to users or groups. This helps implement least-privilege administration by ensuring that personnel receive only the permissions necessary for their responsibilities. Device inventory provides endpoint information, update rings manage Windows Update behavior, and device categories classify devices. RBAC is therefore the appropriate feature for controlling administrative permissions according to specific organizational roles.<\/span><\/p>\n<h3><b>Question 353<\/b><\/h3>\n<p><b>Which Intune endpoint security policy is used to manage BitLocker settings on supported Windows devices?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Antivirus<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Firewall<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disk encryption<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Account protection<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Disk encryption endpoint security policy is designed to configure supported disk encryption settings, including BitLocker-related controls, on managed Windows devices. Administrators can use this policy to establish encryption requirements and configure supported BitLocker behavior across organizational endpoints. Antivirus policies manage malware protection, Firewall policies configure network protection, and Account protection manages supported identity and credential-related settings. Disk encryption is therefore the appropriate endpoint security policy category when administrators need to centrally configure BitLocker and related encryption settings.<\/span><\/p>\n<h3><b>Question 354<\/b><\/h3>\n<p><b>Which Intune capability can identify whether a managed device has sufficient hardware resources for a particular deployment requirement?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Company Portal<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Scope tag<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Requirement rule<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Remote Help<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Requirement rules allow administrators to define conditions that a device must satisfy before a Win32 application can be installed. Supported requirements can include operating system architecture, available disk space, minimum operating system version, and other applicable conditions. This helps prevent software from being deployed to devices that do not meet its technical prerequisites. Company Portal provides user-facing application access, scope tags manage administrative visibility, and Remote Help supports troubleshooting. Requirement rule is therefore the appropriate feature for determining whether a device satisfies predefined installation requirements.<\/span><\/p>\n<h3><b>Question 355<\/b><\/h3>\n<p><b>Which Windows feature allows users to restore previous versions of personal files from automatically created file backups?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">File History<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SmartScreen<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Credential Guard<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Storage Sense<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">File History is a Windows feature that can automatically save copies of selected personal files and allow users to restore previous versions when necessary. It is useful for recovering files that were accidentally modified, deleted, or replaced. SmartScreen provides reputation-based protection, Credential Guard protects sensitive authentication information, and Storage Sense manages storage space by automatically removing certain unnecessary files. File History is therefore the correct Windows feature when the requirement is to maintain recoverable previous versions of user files.<\/span><\/p>\n<h3><b>Question 356<\/b><\/h3>\n<p><b>Which Intune feature provides administrators with a centralized view of device hardware and software information collected from managed endpoints?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Remote Help<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Device inventory<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">App protection policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Enrollment Status Page<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Device inventory provides administrators with information collected from managed endpoints, including supported hardware, operating system, and software details. This information helps IT teams understand the organization&#8217;s device environment, troubleshoot issues, identify device configurations, and support management decisions. Remote Help is designed for remote assistance, app protection policies protect organizational data within supported applications, and the Enrollment Status Page controls deployment progress. Device inventory is therefore the appropriate Intune capability when administrators need centralized information about managed endpoint characteristics.<\/span><\/p>\n<h3><b>Question 357<\/b><\/h3>\n<p><b>Which Windows update feature controls settings such as update deferrals, restart behavior, and installation schedules for managed devices?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Feature update policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Expedite update policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Update ring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Device compliance policy<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Update rings allow administrators to configure Windows Update behavior for managed devices. Depending on supported settings, administrators can control update deferrals, deadlines, restart behavior, active hours, and other servicing options. Feature update policies are used to target specific Windows feature versions, while expedite update policies accelerate deployment of selected quality updates. Compliance policies evaluate whether devices meet organizational requirements rather than directly controlling normal Windows Update behavior. Update ring is therefore the appropriate policy when administrators need to manage general Windows Update servicing behavior.<\/span><\/p>\n<h3><b>Question 358<\/b><\/h3>\n<p><b>Which Intune feature allows administrators to add descriptive information to managed devices so they can be grouped or identified according to organizational needs?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Device cleanup<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Device category<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security baseline<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Conditional Access<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Device categories allow administrators to classify managed devices according to organizational needs. Categories can help users and administrators distinguish between different types of devices and can be useful when organizing device management or applying category-based processes. Device cleanup removes stale records, security baselines configure recommended security settings, and Conditional Access controls access to resources based on defined conditions. Device category is therefore the appropriate Intune feature when an organization needs to classify or identify managed devices according to organizational characteristics.<\/span><\/p>\n<h3><b>Question 359<\/b><\/h3>\n<p><b>Which Microsoft Entra feature can automatically maintain device group membership based on a defined membership rule?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Scope tags<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Assignment filters<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Dynamic device group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Enrollment restrictions<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Dynamic device groups use membership rules to automatically determine which devices belong to a Microsoft Entra group. When a device&#8217;s relevant attributes match the configured rule, the device can be included automatically. This reduces the need for administrators to manually maintain device membership and is useful for targeting Intune policies, applications, and other resources. Scope tags control administrative visibility, assignment filters refine Intune assignments, and enrollment restrictions control which devices can enroll. Dynamic device groups are therefore the correct choice for rule-based automatic device membership.<\/span><\/p>\n<h3><b>Question 360<\/b><\/h3>\n<p><b>Which Intune device action removes organizational data and management from a device while generally preserving personal content?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Retire<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Wipe<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Fresh Start<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Autopilot Reset<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Retire action is designed to remove organizational management and supported corporate data from a device while generally preserving personal user content. It is particularly useful when an organization needs to remove its management from a personally owned device or when a device should no longer access corporate resources. Wipe performs a broader reset and can erase device data, Fresh Start reinstalls Windows with supported removal behavior, and Autopilot Reset prepares a device for reuse while retaining its organizational enrollment state. Retire is therefore the appropriate action for removing organizational control while preserving personal content.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Microsoft MD-102 Exam Dumps and Practice Test Dumps. &nbsp; Question 341 Which Intune feature allows administrators to define a grace period before a device is considered noncompliant? Assignment filter Security baseline Device category Compliance policy action Correct Answer: 4 Explanation Compliance policy actions can define what happens when a device does not meet [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14353"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=14353"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14353\/revisions"}],"predecessor-version":[{"id":14359,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14353\/revisions\/14359"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=14353"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=14353"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=14353"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}