Free MD 100: Modern Device Management Questions and Answers — Questions and Answers
Question 1: Techuisitive Microsoft Endpoint Manager administrator. The company recently installed 5 computers in the common area for employees to check their personal emails or visit unsecure websites. <br> Make sure employees can use Microsoft Edge without signing in. These computers should not allow employees to use other applications. Use which device configuration profile type?
- Device Restriction
- Endpoint Protection
- Kiosk (Correct answer)
- Administrative Templates
Correct answer: Kiosk
A Kiosk device configuration profile in Microsoft Intune is specifically designed to lock down a device for a single purpose or a limited set of applications. This profile type allows administrators to configure a device to run only specific applications (like Microsoft Edge) and prevent users from accessing other parts of the operating system, making it ideal for public-use computers.
Question 2: "You are in charge of the Microsoft Intune-enabled Windows 10 devices. You are required to make sure that only authorized locations can access Microsoft Exchange online.<br> What needs to be configured to fulfill the requirement? "
- None of these
- Create a provisioning package
- Create a device compliance policy
- Create a device configuration profile (Correct answer)
Correct answer: Create a device configuration profile
To restrict access to Microsoft Exchange Online based on location, you would typically use Conditional Access policies, which are often integrated with or managed through device configuration profiles in Intune. A device configuration profile allows you to deploy specific settings, policies, and restrictions to devices, including network access controls or VPN configurations that could enforce location-based access.
Question 3: You are the Microsoft Endpoint Manager administrator at Techuisitve. You administer Windows 10 devices enrolled with Microsoft Intune. The company has a large number of Windows 10 professional devices. All devices running Windows 10 Professional must be upgraded to Windows 10 Enterprise. What should you do?
- None of these
- Create a provisioning package
- Create a device configuration profile (Correct answer)
- Create a device compliance policy
Correct answer: Create a device configuration profile
To upgrade Windows 10 Professional devices to Windows 10 Enterprise using Microsoft Intune, you would create a device configuration profile. This profile type allows you to deploy an 'Edition upgrade' policy, which uses a product key or a subscription activation to perform the upgrade across multiple devices efficiently and at scale.
Question 4: Intune-enrolled Windows 10 laptop. Two device compliance policies for identical devices use the same setting. Policy winner?
- Neither wins
- Last policy applied wins
- Least restrictive wins
- Most restrictive wins (Correct answer)
Correct answer: Most restrictive wins
In Microsoft Intune, when multiple device compliance policies are assigned to the same device and conflict on a particular setting, the most restrictive policy setting takes precedence. This ensures that security and compliance requirements are met at the highest possible level, preventing less secure configurations from being applied.
Question 5: Which offering has Intune?
- Microsoft Enterprise Mobility + Security (Correct answer)
- Microsoft Visual Studio
- Windows Autopilot
- Microsoft Managed Desktop
Correct answer: Microsoft Enterprise Mobility + Security
Microsoft Intune is a key component of Microsoft Enterprise Mobility + Security (EMS), a suite of products designed to help organizations manage and secure their mobile devices, apps, and data. EMS provides a comprehensive set of identity, access, data protection, and device management capabilities, with Intune handling the mobile device and application management aspects.
Question 6: Intune-enrolled Windows 10 laptop. Device configuration and compliance policies use the same setting. Which setting wins?
- Less restrictive setting wins
- Most restrictive setting wins
- Device Compliance Policy setting wins (Correct answer)
- Device Configuration Policy setting wins
Correct answer: Device Compliance Policy setting wins
When there's a conflict between a device configuration policy and a device compliance policy for the same setting on an Intune-enrolled device, the device compliance policy typically takes precedence. Compliance policies are designed to enforce critical security and organizational standards, ensuring that devices meet specific requirements before gaining access to resources.
Question 7: Which Microsoft API integrates Intune with other management consoles?
- Microsoft Graph API (Correct answer)
- REST API
- Windows API
- JSON API
Correct answer: Microsoft Graph API
The Microsoft Graph API is the primary unified API endpoint for accessing data and intelligence across Microsoft 365 services, including Intune. It allows developers and other management consoles to programmatically interact with Intune, retrieve device information, manage policies, and automate tasks, facilitating integration with other IT management systems.
Techuisitive Microsoft Endpoint Manager administrator.
The company recently installed 5 computers in the common area for employees to check their personal emails or visit unsecure websites.
Make sure employees can use Microsoft Edge without signing in.
These computers should not allow employees to use other applications.
Use which device configuration profile type?