MD-101 Microsoft Intune Device Configuration Profiles 1 — Questions and Answers
Question 1: Which profile type in Intune allows administrators to configure Windows Defender Firewall rules for managed devices?
- Device restrictions profile
- Endpoint security — Firewall policy (Correct answer)
- Custom OMA-URI profile
- Identity protection profile
Correct answer: Endpoint security — Firewall policy
Endpoint security Firewall policies in Intune allow granular configuration of Windows Defender Firewall rules across managed devices.
Question 2: An administrator needs to deploy a Wi-Fi profile to iOS and Android devices. Which Intune profile type should be used?
- Device restrictions
- Wi-Fi profile under Device configuration (Correct answer)
- VPN profile
- Email profile
Correct answer: Wi-Fi profile under Device configuration
A Wi-Fi profile under Device configuration in Intune enables administrators to push network credentials and settings to mobile devices automatically.
Question 3: What is the purpose of an OMA-URI setting in a custom Intune configuration profile?
- To configure Azure AD Conditional Access rules
- To apply settings not exposed in Intune's built-in profile UI using raw MDM CSP paths (Correct answer)
- To push scripts to managed devices
- To configure BitLocker recovery keys
Correct answer: To apply settings not exposed in Intune's built-in profile UI using raw MDM CSP paths
OMA-URI settings allow administrators to configure MDM CSP paths directly when Intune's built-in templates don't expose the needed setting.
Question 4: Which Intune profile type enforces Windows Hello for Business on enrolled Windows 10/11 devices?
- Device restrictions profile
- Identity protection profile (Windows Hello for Business)
- Endpoint security — Account protection
- Both B and C are valid (Correct answer)
Correct answer: Both B and C are valid
Both Identity protection profiles and Endpoint security Account protection policies can configure Windows Hello for Business settings in Intune.
Question 5: A configuration profile assigned to a device group conflicts with a profile assigned to a user group. Which takes precedence by default?
- User group assignment always wins
- Device group assignment always wins (Correct answer)
- The profile with higher priority number wins
- The most recently created profile wins
Correct answer: Device group assignment always wins
When a device-group-assigned profile conflicts with a user-group-assigned profile for the same setting, the device group assignment takes precedence in Intune.
Question 6: Which Intune report shows which devices have successfully applied a specific configuration profile?
- Device compliance report
- Device configuration — per-profile assignment status report (Correct answer)
- Endpoint analytics — Device health
- Windows Update compliance report
Correct answer: Device configuration — per-profile assignment status report
The per-profile assignment status report under Device configuration shows each device's status (succeeded, failed, pending) for that specific profile.
Which profile type in Intune allows administrators to configure Windows Defender Firewall rules for managed devices?