MD-101 Cheat Sheet 2026
The 30 highest-yield MD-101 facts, distilled from real exam questions. Print it, save it as a PDF, or study it here — free, no sign-up.
60 questions
100 min time limit
70.00% to pass
- Which Azure AD Conditional Access signal can assess device risk using Microsoft Defender for Endpoint threat intelligence? → Device risk via Microsoft Defender for Endpoint integration
- Which Microsoft Defender for Endpoint capability scores and prioritizes device security misconfigurations and vulnerabilities? → Microsoft Defender Vulnerability Management (MDVM) with Secure Score for Devices
- An administrator wants to deploy a Win32 application via Intune to specific devices. What file format must the app be packaged in before uploading to Intune? → .intunewin
- An administrator needs to ensure that only compliant devices can access corporate resources in Microsoft 365. Which Intune feature should be configured? → Conditional Access policies
- Which component of the Enrollment Status Page (ESP) tracks app installation progress during Autopilot? → Device setup phase — App installations section
- What does Microsoft Defender for Endpoint's 'Endpoint Detection and Response (EDR)' capability primarily provide? → Post-breach detection, investigation, and response capabilities for advanced threats
- Which Windows Update for Business setting controls the maximum number of days a feature update can be deferred? → 365 days
- What must users do on an unenrolled iOS device before App Protection Policies take effect in apps like Outlook? → Sign in with their Azure AD corporate account within the Intune-managed app
- Which Intune App Protection Policy conditional launch setting blocks jailbroken or rooted devices from accessing corporate app data? → Jailbroken/rooted devices — Block access or Wipe data
- Which tool converts Win32 app installers into the .intunewin format required for Intune deployment? → Microsoft Win32 Content Prep Tool (IntuneWinAppUtil.exe)
- A user reports that their Azure AD-joined Windows 11 device is not receiving Intune policies. What is the FIRST step to diagnose this? → Check the device compliance status in Intune portal
- Which Azure AD feature integrates with Intune compliance status to block non-compliant devices from accessing corporate resources? → Conditional Access requiring a compliant device
- What is the maximum number of devices a standard user can join to Azure AD by default, relevant to Autopilot user-driven deployments? → 10
- Which PowerShell cmdlet is used to check if a device is enrolled in Windows Autopilot? → Get-WindowsAutopilotInfo
- In a co-management scenario where both Configuration Manager and Intune apply settings to the same area, what determines which settings take effect? → The configured workload authority slider determines which platform's settings apply
- Which Azure AD Connect feature is required to enable Hybrid Azure AD Join for co-management scenarios? → Azure AD Connect with device writeback enabled
- Which tool can you use to analyze Windows Autopilot deployment failures and retrieve detailed event logs from a device? → MDMDiagnosticsTool.exe
- An organization deploys Outlook with an App Protection Policy requiring PIN. A user says they are not prompted for a PIN. What is the most likely cause? → The App Protection Policy is not assigned to the user's Azure AD group
- Which compliance policy action sends an automatic notification email to users when their device becomes non-compliant? → Send email to end user — under Actions for noncompliance
- Which Intune integration enables security administrators to manage Microsoft Defender for Endpoint settings directly from the Intune admin center? → Microsoft Defender for Endpoint — Intune connector via security settings management
- Which App Protection Policy setting prevents users from saving corporate files to personal cloud storage like Google Drive? → Save copies of org data — restrict to approved locations only
- An administrator needs to ensure that Intune-enrolled iOS devices automatically install a required app. Which assignment type should be used? → Required
- A user on a shared Windows 11 kiosk device should only be able to run one specific UWP application. Which Intune configuration should you apply? → Kiosk mode – Single app kiosk
- What happens to a device's Autopilot registration when it is deleted from Azure AD? → The device loses its Autopilot registration and must be re-registered
- What is the Windows Long-Term Servicing Channel (LTSC) primarily designed for? → Specialized devices (medical, industrial, kiosks) that require stability over new features
- Which Microsoft Endpoint Manager feature allows you to set a maximum OS version that a device must not exceed to remain compliant? → Compliance policies
- Which setting in an Autopilot deployment profile controls whether users receive local administrator rights after OOBE? → Account type: Administrator or Standard User
- Which setting in Intune Update Rings controls whether users can see and dismiss Windows Update notifications? → User Update Notification — control update notifications displayed to user
- An Intune compliance policy sets minimum OS version to Windows 10 21H2. A device running 21H1 is enrolled. What is the device's compliance state? → Not compliant
- An organization onboards devices to Microsoft Defender for Endpoint. Which Intune policy type deploys the MDE onboarding configuration package? → Endpoint detection and response (EDR) policy under Endpoint security
Turn these facts into recall:
Was this helpful?