MD-101 Cheat Sheet 2026

The 30 highest-yield MD-101 facts, distilled from real exam questions. Print it, save it as a PDF, or study it here — free, no sign-up.

60 questions
100 min time limit
70.00% to pass
  1. Which Azure AD Conditional Access signal can assess device risk using Microsoft Defender for Endpoint threat intelligence? Device risk via Microsoft Defender for Endpoint integration
  2. Which Microsoft Defender for Endpoint capability scores and prioritizes device security misconfigurations and vulnerabilities? Microsoft Defender Vulnerability Management (MDVM) with Secure Score for Devices
  3. An administrator wants to deploy a Win32 application via Intune to specific devices. What file format must the app be packaged in before uploading to Intune? .intunewin
  4. An administrator needs to ensure that only compliant devices can access corporate resources in Microsoft 365. Which Intune feature should be configured? Conditional Access policies
  5. Which component of the Enrollment Status Page (ESP) tracks app installation progress during Autopilot? Device setup phase — App installations section
  6. What does Microsoft Defender for Endpoint's 'Endpoint Detection and Response (EDR)' capability primarily provide? Post-breach detection, investigation, and response capabilities for advanced threats
  7. Which Windows Update for Business setting controls the maximum number of days a feature update can be deferred? 365 days
  8. What must users do on an unenrolled iOS device before App Protection Policies take effect in apps like Outlook? Sign in with their Azure AD corporate account within the Intune-managed app
  9. Which Intune App Protection Policy conditional launch setting blocks jailbroken or rooted devices from accessing corporate app data? Jailbroken/rooted devices — Block access or Wipe data
  10. Which tool converts Win32 app installers into the .intunewin format required for Intune deployment? Microsoft Win32 Content Prep Tool (IntuneWinAppUtil.exe)
  11. A user reports that their Azure AD-joined Windows 11 device is not receiving Intune policies. What is the FIRST step to diagnose this? Check the device compliance status in Intune portal
  12. Which Azure AD feature integrates with Intune compliance status to block non-compliant devices from accessing corporate resources? Conditional Access requiring a compliant device
  13. What is the maximum number of devices a standard user can join to Azure AD by default, relevant to Autopilot user-driven deployments? 10
  14. Which PowerShell cmdlet is used to check if a device is enrolled in Windows Autopilot? Get-WindowsAutopilotInfo
  15. In a co-management scenario where both Configuration Manager and Intune apply settings to the same area, what determines which settings take effect? The configured workload authority slider determines which platform's settings apply
  16. Which Azure AD Connect feature is required to enable Hybrid Azure AD Join for co-management scenarios? Azure AD Connect with device writeback enabled
  17. Which tool can you use to analyze Windows Autopilot deployment failures and retrieve detailed event logs from a device? MDMDiagnosticsTool.exe
  18. An organization deploys Outlook with an App Protection Policy requiring PIN. A user says they are not prompted for a PIN. What is the most likely cause? The App Protection Policy is not assigned to the user's Azure AD group
  19. Which compliance policy action sends an automatic notification email to users when their device becomes non-compliant? Send email to end user — under Actions for noncompliance
  20. Which Intune integration enables security administrators to manage Microsoft Defender for Endpoint settings directly from the Intune admin center? Microsoft Defender for Endpoint — Intune connector via security settings management
  21. Which App Protection Policy setting prevents users from saving corporate files to personal cloud storage like Google Drive? Save copies of org data — restrict to approved locations only
  22. An administrator needs to ensure that Intune-enrolled iOS devices automatically install a required app. Which assignment type should be used? Required
  23. A user on a shared Windows 11 kiosk device should only be able to run one specific UWP application. Which Intune configuration should you apply? Kiosk mode – Single app kiosk
  24. What happens to a device's Autopilot registration when it is deleted from Azure AD? The device loses its Autopilot registration and must be re-registered
  25. What is the Windows Long-Term Servicing Channel (LTSC) primarily designed for? Specialized devices (medical, industrial, kiosks) that require stability over new features
  26. Which Microsoft Endpoint Manager feature allows you to set a maximum OS version that a device must not exceed to remain compliant? Compliance policies
  27. Which setting in an Autopilot deployment profile controls whether users receive local administrator rights after OOBE? Account type: Administrator or Standard User
  28. Which setting in Intune Update Rings controls whether users can see and dismiss Windows Update notifications? User Update Notification — control update notifications displayed to user
  29. An Intune compliance policy sets minimum OS version to Windows 10 21H2. A device running 21H1 is enrolled. What is the device's compliance state? Not compliant
  30. An organization onboards devices to Microsoft Defender for Endpoint. Which Intune policy type deploys the MDE onboarding configuration package? Endpoint detection and response (EDR) policy under Endpoint security
Was this helpful?