MD-100 100: Modern Device Management 3 — Questions and Answers
Question 1: An organization uses Windows Autopilot for device provisioning. Which Azure AD feature must be enabled for Autopilot self-deploying mode?
- Azure AD B2C
- Multi-factor Authentication
- Azure AD automatic enrollment in Intune (Correct answer)
- Azure AD Privileged Identity Management
Correct answer: Azure AD automatic enrollment in Intune
Autopilot requires Azure AD automatic MDM enrollment to be configured so devices automatically enroll in Intune during the OOBE process.
Question 2: Which Intune feature allows administrators to run PowerShell scripts on enrolled Windows 10 devices?
- Device Configuration Profiles
- PowerShell Scripts under Devices (Correct answer)
- Endpoint Analytics
- Compliance Policies
Correct answer: PowerShell Scripts under Devices
Intune's PowerShell Scripts feature (under Devices > Scripts) allows admins to deploy and run PowerShell scripts on managed Windows 10 devices.
Question 3: A Windows 10 device is showing the error 'MDM enrollment failed: 0x80180026.' What is the likely cause?
- The device is not connected to the internet
- The Intune license is not assigned to the user
- The device already has an MDM enrollment (Correct answer)
- The device does not meet minimum OS requirements
Correct answer: The device already has an MDM enrollment
Error 0x80180026 typically occurs when a device already has an existing MDM enrollment that conflicts with the new enrollment attempt.
Question 4: Which Windows Update for Business policy setting controls when feature updates are installed on devices?
- Quality Update Deferral Period
- Feature Update Deferral Period (Correct answer)
- Update Ring Deadline
- Pause Feature Updates
Correct answer: Feature Update Deferral Period
The Feature Update Deferral Period policy delays installation of new Windows feature updates for a specified number of days after release.
Question 5: An administrator wants to prevent users on shared Windows 10 kiosk devices from accessing settings or installing apps. Which feature should be configured?
- Assigned Access (Kiosk Mode) (Correct answer)
- Windows Hello for Business
- AppLocker
- User Account Control
Correct answer: Assigned Access (Kiosk Mode)
Assigned Access restricts a Windows 10 account to run only one app (single-app kiosk) or a limited set of apps (multi-app kiosk).
Question 6: Which protocol does the Intune Management Extension use to communicate with Microsoft Intune?
- LDAP over SSL
- HTTPS on port 443 (Correct answer)
- RDP on port 3389
- WMI over DCOM
Correct answer: HTTPS on port 443
The Intune Management Extension communicates with Intune services over HTTPS on port 443, the standard secure web traffic port.
Question 7: A company wants to enable co-management for Windows 10 devices already managed by SCCM. What is the FIRST prerequisite to configure?
- Deploy the Intune Company Portal to all devices
- Onboard SCCM to Microsoft Endpoint Manager and enable co-management (Correct answer)
- Unenroll devices from SCCM before enrolling in Intune
- Purchase Intune standalone licenses for all devices
Correct answer: Onboard SCCM to Microsoft Endpoint Manager and enable co-management
Co-management requires attaching SCCM (Configuration Manager) to Microsoft Endpoint Manager (tenant attach) and enabling co-management in the SCCM console.
An organization uses Windows Autopilot for device provisioning.
Which Azure AD feature must be enabled for Autopilot self-deploying mode?