MD-100 100: Modern Device Management 2 — Questions and Answers
Question 1: A company wants to enforce BitLocker encryption on all Windows 10 devices enrolled in Intune. Which Intune policy type should be configured?
- Device Compliance Policy
- Endpoint Protection Configuration Profile (Correct answer)
- Device Restriction Profile
- Windows Information Protection Policy
Correct answer: Endpoint Protection Configuration Profile
Endpoint Protection Configuration Profiles in Intune include BitLocker settings to enforce disk encryption on managed Windows devices.
Question 2: Which Windows 10 edition is the MINIMUM requirement for Azure AD Join?
- Windows 10 Home
- Windows 10 Pro (Correct answer)
- Windows 10 Enterprise
- Windows 10 Education
Correct answer: Windows 10 Pro
Azure AD Join is supported on Windows 10 Pro, Enterprise, and Education editions, with Pro being the minimum required edition.
Question 3: An administrator needs to deploy a required app to all enrolled Intune devices without user interaction. Which assignment type should be used?
- Available for enrolled devices
- Required (Correct answer)
- Uninstall
- Available with or without enrollment
Correct answer: Required
The 'Required' assignment type in Intune automatically installs the app on targeted devices without requiring user action.
Question 4: A Windows 10 device is Hybrid Azure AD Joined. What does this mean?
- The device is joined to Azure AD only
- The device is joined to on-premises AD and registered in Azure AD (Correct answer)
- The device uses a local account with Azure AD sync
- The device is managed by both Intune and SCCM simultaneously
Correct answer: The device is joined to on-premises AD and registered in Azure AD
Hybrid Azure AD Join means the device is joined to on-premises Active Directory AND registered/joined in Azure AD, enabling both traditional and cloud management.
Question 5: Which tool allows administrators to configure Windows 10 devices using XML-based provisioning packages without MDM enrollment?
- Windows Configuration Designer (Correct answer)
- Microsoft Endpoint Manager
- Group Policy Management Console
- Windows Deployment Services
Correct answer: Windows Configuration Designer
Windows Configuration Designer creates provisioning packages (.ppkg files) that can configure Windows 10 devices without requiring MDM enrollment.
Question 6: A user's Windows 10 device is enrolled in Intune but shows as 'Not Compliant.' What is the FIRST step to diagnose the issue?
- Wipe and re-enroll the device
- Check the device compliance policy and the specific rule that failed (Correct answer)
- Remove the user from all Azure AD groups
- Reinstall the Intune Company Portal app
Correct answer: Check the device compliance policy and the specific rule that failed
Reviewing the compliance policy details in Intune shows which specific rule the device failed, providing the most direct path to resolution.
Question 7: Which Windows 10 feature allows IT to reset a device to factory settings while preserving the user's personal data?
- Fresh Start
- Reset this PC (Keep my files) (Correct answer)
- Windows Recovery Environment
- System Restore
Correct answer: Reset this PC (Keep my files)
'Reset this PC' with the 'Keep my files' option reinstalls Windows while retaining personal files, though apps and settings are removed.
A company wants to enforce BitLocker encryption on all Windows 10 devices enrolled in Intune.
Which Intune policy type should be configured?