Managing Modern Desktops (MD-101)

FREE Managing Modern Desktops (MD-101) Administrator Questions and Answers

0%

You are employed by a company that has a Microsoft 365 subscription. The membership includes Enterprise Mobility and Security. Members of a group called Marketing utilize iOS-powered devices. It would help if you guaranteed that members of the group Marketing might install Microsoft OneDrive using Company Portal. What course of action would you take?

Correct!
Wrong!

By adding the Microsoft OneDrive app as a featured app in the Company Portal, you ensure that members of the Marketing group can easily find and install the app on their iOS devices. This allows them to access and use Microsoft OneDrive as required.

The device is the name of a device you have that is running Windows 10 Enterprise. The device has an Azure Active Directory registration (Azure AD). Can you provide a command-line program that you would employ to verify if this Devicel is connected to Azure AD?

Correct!
Wrong!

The “dsregcmd” command-line tool can be used to confirm if a Windows 10 device is Azure AD joined. By running the “dsregcmd” command, you can retrieve information about the device’s registration status with Azure AD, including whether it is Azure AD joined.

The network operated by your company is set up as an Active Directory Domain Services (AD DS) domain. The network also has an Azure Active Directory (Azure AD) domain. All of the domain customers have joined hybrid Azure AD. Most of the company’s on-premises clients have recently received Windows 10 upgrades. Microsoft 365 Enterprise E5 license is applied. All client machines are set up to run the System Center Configuration Manager (SCCM) client. Using SCCM, you wish to distribute settings to domain clients. The company has a Microsoft Defender Advanced Threat Protection (ATP) online service subscription. You must generate an onboarding configuration file to set up onboarding to support ATP for domain-joined clients. Which of the following options would you employ to create the file?

Correct!
Wrong!

The SCCM Configuration Manager console allows you to manage and deploy configurations to domain clients, including configuring onboarding for ATP.

Twenty-five thousand devices are present in OrganizationA. Windows 10 is operating on each device. All Windows 10 devices are managed using System Center Configuration Manager (SCCM), and Microsoft Intune is utilized to co-manage the devices. The workloads moved to Microsoft Intune are listed below: – Compliance regulations Windows Update guidelines. All of the gadgets run Windows 10. They are all linked to the hybrid Azure Active Directory (Azure AD). Every device has been set up for Upgrade Readiness. You must create a report that includes data on device enrollment and compliance. The details that must be included in this report are the device’s name, managed by; compliance -Date of Enrollment -Last Check-in. Choose the instrument you’d use with the least administrative expenditure in mind.

Correct!
Wrong!

To craft a report that reflects device enrollment and compliance information with the least administrative costs spent, you would use the Microsoft Intune Data Warehouse. The Data Warehouse provides a comprehensive set of APIs and data entities that allow you to extract data from Microsoft Intune and create custom reports. It provides a more flexible and scalable option for generating reports and accessing historical data compared to other tools.

With the Microsoft Intune Data Warehouse, you can query and retrieve the required information such as device name, managed by, compliance status, enrollment date, and last check-in. This allows you to create custom reports tailored to your organization’s needs while minimizing administrative efforts and costs.

Computers in your company are set up to connect to a network. The machines are powered by Windows 10. The PCs are set up with hybrid-linked Active Directory Domain Services (AD DS) and Azure Active Directory domains. The exact System Center Operations Manager management group manages all domain PCs. DefWorkspace is the name of an Azure Log Analytics workspace. You had chosen this workspace while installing the Microsoft Monitoring Agent on your domain machines. Additionally, data from the Operations Manager management group may be received by this workspace. Where you want the event log and performance data to be written is created and named SpecWorkspace in another Log Analytics workspace. It must be ensured that the domain computers continue to deliver data to DefWorkspace and the new workspace simultaneously. Which of the following will you use to set up this, please?

Correct!
Wrong!

To configure the domain computers to send data to the new Log Analytics workspace (SpecWorkspace) while also continuing to send data to the existing workspace (DefWorkspace), you would use the Microsoft Monitoring Agent.

The Microsoft Monitoring Agent is responsible for collecting and sending data from the domain computers to the specified Log Analytics workspaces. During the installation process of the agent, you can specify the workspace(s) to which the agent should send data. In this case, you would configure the Microsoft Monitoring Agent on the domain computers to send data to both DefWorkspace and SpecWorkspace.

By configuring the agent to send data to multiple workspaces, you can ensure that the event log and performance data from the domain computers are written to both workspaces simultaneously. This allows you to maintain the data flow to the existing workspace while also sending the desired data to the new workspace.

Two thousand five hundred devices are in Organization A. Windows 10 operates on every device. These devices have a hybrid-linked Windows Active Directory and Azure Active Directory. All workers are permitted to use Enterprise State Roaming (ESR). The Windows 10 devices are organized in an organizational unit (OU) called OU1. OU1 is connected to a Group Policy object called PolicyI. The following conditions must be satisfied to configure PolicyI: -Avoid having the ESR sync wireless profiles. -Reduce disruption from other ESR sync groups. Choose the setting you should configure from the options below.

Correct!
Wrong!

To meet the requirements of preventing ESR from syncing wireless profiles and minimizing interference with other ESR sync groups, you should configure the “Do not sync app settings” setting in the Group Policy object (GPO) named PolicyI.

By enabling the “Do not sync app settings” setting, you ensure that the ESR feature does not synchronize app settings, which includes wireless profiles. This prevents the syncing of wireless profiles for the devices in the OU1 organizational unit. Additionally, by not syncing app settings, you minimize interference with other ESR sync groups, allowing for more focused and specific synchronization of settings. (Diazepam)

Therefore, configuring the “Do not sync app settings” setting in PolicyI will help meet the given requirements.

Four hundred mobile devices belonging to OrganizationA are active on the network. Both the iOS and Android operating systems are available on these devices. You want to implement Microsoft Intune for mobile device management (MDM). It would help if you disallowed devices running an IOS older than 12.0 on every device enrolled in Microsoft Intune. Which of the following choices would you choose?

Correct!
Wrong!

To prevent devices running an iOS version older than 12.0 from enrolling in Microsoft Intune, you would use a device compliance policy. A device compliance policy allows you to define and enforce specific device requirements and settings. In this case, you can create a device compliance policy that includes a condition to check the iOS version, specifying a minimum version of 12.0. Any device with an iOS version older than 12.0 would be considered non-compliant and prevented from enrolling in Microsoft Intune.