Exam MD-101: Managing Modern Desktops — Questions and Answers
Question 1: Which Azure AD feature automatically marks a sign-in as risky when it detects unusual travel or anonymous IP usage?
- Azure AD Smart Lockout
- Azure AD Conditional Access named locations
- Azure AD Identity Protection (Correct answer)
- Multi-Factor Authentication
Correct answer: Azure AD Identity Protection
Azure AD Identity Protection uses machine learning to detect risky sign-ins and can block or require MFA based on detected risk levels.
Question 2: An administrator configures an Update Ring with a 10-day quality update deferral and a 30-day feature update deferral. A quality update is released on March 1. When will devices receive it?
- April 1
- March 1
- March 31
- March 11 (Correct answer)
Correct answer: March 11
With a 10-day quality update deferral, devices will receive the March 1 update beginning March 11, after the deferral period expires.
Question 3: A help desk technician needs to remotely assist a user with a Windows 10 device enrolled in Intune without interrupting the user's session. Which feature should be used?
- Remote Control in MECM
- Intune Remote Help (Correct answer)
- Quick Assist
- Windows Remote Assistance
Correct answer: Intune Remote Help
Intune Remote Help provides a cloud-based remote assistance solution that integrates with role-based access control in Intune.
Question 4: A Conditional Access policy is set to 'Report-only' mode. What effect does it have on users?
- It applies only to pilot group users
- It enforces MFA but does not block access
- It blocks access and logs the result
- It evaluates the policy and logs what would have happened without enforcing any controls (Correct answer)
Correct answer: It evaluates the policy and logs what would have happened without enforcing any controls
Report-only mode evaluates Conditional Access policies and records results in sign-in logs without enforcing any grant or session controls on users.
Question 5: A company wants to prevent users from installing unapproved apps on Windows 11 devices enrolled in Intune. Which feature should you configure?
- Windows Defender Firewall
- BitLocker encryption
- Windows Sandbox
- AppLocker or WDAC policies (Correct answer)
Correct answer: AppLocker or WDAC policies
AppLocker or Windows Defender Application Control (WDAC) policies restrict which applications users can run on managed devices.
Question 6: Which Intune compliance setting specifically checks that Secure Boot is enabled on Windows devices?
- Require BitLocker
- Require code integrity
- Require Windows Defender Credential Guard
- Require Secure Boot to be enabled on the device (Correct answer)
Correct answer: Require Secure Boot to be enabled on the device
The 'Require Secure Boot to be enabled on the device' compliance setting verifies that the device's firmware security feature is active.
Question 7: An administrator needs to deploy a Wi-Fi profile to iOS and Android devices. Which Intune profile type should be used?
- Email profile
- Wi-Fi profile under Device configuration (Correct answer)
- Device restrictions
- VPN profile
Correct answer: Wi-Fi profile under Device configuration
A Wi-Fi profile under Device configuration in Intune enables administrators to push network credentials and settings to mobile devices automatically.
Question 8: What is the purpose of assigning a device to a user in Windows Autopilot?
- To pre-assign user credentials so no login is required
- To associate a primary user with the device for a pre-assigned user experience during OOBE (Correct answer)
- To enable co-management with Configuration Manager
- To license the device for Windows Enterprise
Correct answer: To associate a primary user with the device for a pre-assigned user experience during OOBE
Pre-assigning a user to an Autopilot device populates the sign-in page with the user's email during OOBE, reducing steps for the end user.
Question 9: What is the minimum Configuration Manager current branch version required to enable co-management?
- Configuration Manager version 2002
- Configuration Manager version 2012 R2
- Configuration Manager version 1902
- Configuration Manager version 1710 (Correct answer)
Correct answer: Configuration Manager version 1710
Co-management support was introduced in Configuration Manager current branch version 1710, making it the minimum supported version.
Question 10: Which Autopilot profile setting prevents users from skipping the privacy settings page during OOBE?
- Skip AD connectivity check
- User account type = Standard
- Convert all targeted devices to Autopilot = Yes
- Privacy settings = Hide (Correct answer)
Correct answer: Privacy settings = Hide
Setting Privacy settings to Hide in the Autopilot profile suppresses the privacy settings screen during OOBE, enforcing a consistent setup experience.
Question 11: What are the two primary paths to enable co-management for existing environments?
- Enrolling new devices via Autopilot or migrating existing Configuration Manager clients to co-management (Correct answer)
- Modern provisioning for new devices and legacy provisioning for older hardware
- Azure AD Join and Hybrid Azure AD Join enrollment paths
- Cloud-only management rollout and on-premises management consolidation
Correct answer: Enrolling new devices via Autopilot or migrating existing Configuration Manager clients to co-management
Co-management is achieved either by enrolling new devices through Windows Autopilot or by enabling Intune enrollment on existing Configuration Manager-managed clients.
Question 12: Which report in Intune provides a consolidated view of device compliance status across all platforms?
- Device enrollment report
- Endpoint analytics — Device performance
- Compliance — Monitor > Device compliance report (Correct answer)
- Azure AD — Devices > All devices
Correct answer: Compliance — Monitor > Device compliance report
The Device compliance report under Compliance > Monitor in Intune shows aggregate and per-device compliance status across all enrolled platforms.
Question 13: WeylandIndustries.com is the Active Directory domain for your business. Microsoft Azure Active Directory (Azure AD) and the domain are synchronised, and Microsoft Intune has been installed on every workstation. <br> You are getting ready to wipe some business-related gadgets. <br> The Wipe action is supported by which of the following operating systems? Decide which options apply.
- Windows 10 (Correct answer)
- iOS (Correct answer)
- Windows Vista
- Windows 8.1
Correct answer: Windows 10
Both Windows 10 and iOS operating systems support the Wipe action in Microsoft Intune. The Wipe action allows you to remotely wipe company data and settings from devices that are enrolled in Intune. This can be useful in scenarios where a device is lost, stolen, or needs to be securely wiped before being reissued or retired.
Question 14: Which Intune report shows the Autopilot deployment status for individual devices including each ESP phase result?
- Device configuration state report
- Windows Autopilot deployments report (Correct answer)
- Device compliance report
- Enrollment failures report
Correct answer: Windows Autopilot deployments report
The Windows Autopilot deployments report in Intune shows per-device deployment status including each ESP phase outcome and error codes.
Question 15: What network requirement must be met for Windows Autopilot to function during OOBE?
- The device must have internet connectivity to reach Microsoft cloud services (Correct answer)
- An on-premises MDM server must be accessible
- A domain controller must be reachable on the local network
- A DHCP server with PXE options must be available
Correct answer: The device must have internet connectivity to reach Microsoft cloud services
Autopilot requires internet connectivity during OOBE to contact Microsoft Deployment Service and Azure AD for device registration and profile download.
Question 16: An organization wants to block access from legacy authentication clients (e.g., SMTP, IMAP) to prevent credential spray attacks. What should be configured?
- Block all mobile device enrollment
- Azure AD Password Protection policy
- MFA required for all sign-ins
- Conditional Access policy blocking legacy authentication via client apps condition (Correct answer)
Correct answer: Conditional Access policy blocking legacy authentication via client apps condition
A Conditional Access policy targeting 'Other clients' in the Client apps condition and using Block access blocks legacy authentication protocols that don't support MFA.
Question 17: Which Windows Autopilot deployment mode allows a technician to pre-provision a device so the end user only needs to complete minimal setup steps?
- User-driven mode
- Reset mode
- White glove (pre-provisioning) mode (Correct answer)
- Self-deploying mode
Correct answer: White glove (pre-provisioning) mode
White glove (pre-provisioning) mode lets a technician complete device-level provisioning before delivering the device to the end user.
Question 18: A co-managed device shows 'MDM Enrolled: No' in Configuration Manager despite co-management being configured. What is the most likely root cause?
- The device is running a Windows version below Windows 10 1709
- The Configuration Manager client is uninstalled or reporting in an error state
- Automatic MDM enrollment is not properly configured in Azure AD or the relevant Group Policy, preventing silent enrollment (Correct answer)
- The device lacks internet connectivity to reach Intune enrollment endpoints
Correct answer: Automatic MDM enrollment is not properly configured in Azure AD or the relevant Group Policy, preventing silent enrollment
The most common reason existing Configuration Manager clients fail to enroll in Intune is that automatic MDM enrollment was not configured in Azure AD user scope settings or via Group Policy, so the silent enrollment never triggers.
Question 19: Which Intune endpoint security policy type configures Microsoft Defender Antivirus scan settings and exclusions?
- Device restrictions profile
- Endpoint detection and response (EDR) policy
- Security baseline
- Antivirus policy under Endpoint security (Correct answer)
Correct answer: Antivirus policy under Endpoint security
Endpoint security Antivirus policies in Intune configure Microsoft Defender Antivirus settings including scan type, schedule, exclusions, and cloud protection level.
Question 20: What is 'MAM without enrollment' (MAM-WE) specifically designed for?
- Enrolling devices without user interaction
- Deploying apps to devices that cannot enroll
- Protecting corporate data in Office apps on personal (BYOD) devices that are not enrolled in Intune MDM (Correct answer)
- Applying compliance policies to unenrolled devices
Correct answer: Protecting corporate data in Office apps on personal (BYOD) devices that are not enrolled in Intune MDM
MAM-WE allows App Protection Policies to protect corporate data in supported apps on personal devices without requiring full MDM device enrollment.
Question 21: What is the maximum number of devices a standard user can join to Azure AD by default, relevant to Autopilot user-driven deployments?
- 20
- 5
- Unlimited
- 10 (Correct answer)
Correct answer: 10
By default, Azure AD allows users to join up to 10 devices, though this limit can be changed in Azure AD settings.
Question 22: Which Intune feature prevents users from copying corporate data from a managed app and pasting it into a personal app?
- Device compliance policy
- App Protection Policy — Restrict cut, copy, and paste (Correct answer)
- Windows Information Protection
- Conditional Access
Correct answer: App Protection Policy — Restrict cut, copy, and paste
App Protection Policies include data transfer restrictions that control cut, copy, and paste operations between managed (corporate) and unmanaged (personal) apps.
Question 23: What information does the Microsoft Defender for Endpoint 'Device Inventory' in the Microsoft 365 Defender portal provide?
- A report of all Intune compliance violations
- A list of all Azure AD users and their devices
- An inventory of all installed apps across the organization
- A comprehensive list of onboarded devices with risk level, OS version, and last seen information (Correct answer)
Correct answer: A comprehensive list of onboarded devices with risk level, OS version, and last seen information
The Device Inventory in Microsoft 365 Defender shows all MDE-onboarded devices with risk levels, exposure scores, OS details, and last activity timestamps.
Question 24: What happens to a device's Autopilot registration when it is deleted from Azure AD?
- Nothing changes; the registration persists independently
- The device keeps its Autopilot profile but loses Intune enrollment
- The Autopilot profile is automatically re-applied on next boot
- The device loses its Autopilot registration and must be re-registered (Correct answer)
Correct answer: The device loses its Autopilot registration and must be re-registered
Deleting a device from Azure AD removes the associated Autopilot registration, requiring the hardware hash to be re-uploaded for future Autopilot provisioning.
Question 25: Which Autopilot deployment mode is designed for kiosk or shared devices that require no user affinity?
- Hybrid Azure AD join
- User-driven Azure AD join
- Pre-provisioned mode
- Self-deploying mode (Correct answer)
Correct answer: Self-deploying mode
Self-deploying mode provisions a device with no user affinity, making it ideal for kiosks, digital signage, and shared devices.
Question 26: A company wants to deploy Windows 11 to new devices using Windows Autopilot. Which Azure AD join type allows devices to be managed by Intune without requiring a hybrid configuration?
- Azure AD Join (Correct answer)
- Domain Join
- Hybrid Azure AD Join
- Workplace Join
Correct answer: Azure AD Join
Azure AD Join (cloud-only) allows devices to be fully managed by Intune without requiring on-premises Active Directory connectivity.
Question 27: Which component of the Enrollment Status Page (ESP) tracks app installation progress during Autopilot?
- Security baseline phase
- Device setup phase — App installations section (Correct answer)
- Device preparation phase
- Account setup phase
Correct answer: Device setup phase — App installations section
The Device Setup phase of the ESP includes an App installations section that tracks required apps deployed via Intune during Autopilot.
Question 28: Which Intune Delivery Optimization profile setting controls what percentage of upload bandwidth a device uses to share update content with peers?
- Cache server hostname
- Max upload bandwidth (percentage of bandwidth) (Correct answer)
- Minimum background bandwidth percentage
- Max cache size percentage
Correct answer: Max upload bandwidth (percentage of bandwidth)
The 'Max upload bandwidth (percentage of bandwidth)' setting in Delivery Optimization profiles limits how much of the device's upload bandwidth is used for P2P sharing.
Question 29: How many distinct co-management workloads can be individually configured in Microsoft Endpoint Manager?
- 6 workloads
- 4 workloads
- 10 workloads
- 7 workloads (Correct answer)
Correct answer: 7 workloads
There are 7 co-management workloads: Compliance policies, Device Configuration, Endpoint Protection, Resource Access Policies, Office Click-to-Run apps, Windows Update policies, and Client apps.
Exam MD-101: Managing Modern Desktops
MD-101 validates IT professionals' ability to deploy Windows clients, manage identity and access, configure compliance policies and configuration profiles, maintain and protect devices, and manage apps in enterprise environments. This exam retired September 30, 2023 and was replaced by MD-102.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds