MD-101 Co-management with Microsoft Endpoint Configuration Manager 1 — Questions and Answers
Question 1: What is co-management in the context of Microsoft endpoint management?
- Managing devices with both on-premises AD and Azure AD simultaneously
- Simultaneously managing Windows devices with both Configuration Manager and Microsoft Intune (Correct answer)
- Using two different MDM solutions for different device types within an organization
- A method to manage both Windows and macOS devices from a single unified console
Correct answer: Simultaneously managing Windows devices with both Configuration Manager and Microsoft Intune
Co-management allows Windows 10/11 devices to be concurrently managed by both Configuration Manager and Microsoft Intune, enabling a gradual transition to cloud management.
Question 2: What are the two primary paths to enable co-management for existing environments?
- Azure AD Join and Hybrid Azure AD Join enrollment paths
- Enrolling new devices via Autopilot or migrating existing Configuration Manager clients to co-management (Correct answer)
- Modern provisioning for new devices and legacy provisioning for older hardware
- Cloud-only management rollout and on-premises management consolidation
Correct answer: Enrolling new devices via Autopilot or migrating existing Configuration Manager clients to co-management
Co-management is achieved either by enrolling new devices through Windows Autopilot or by enabling Intune enrollment on existing Configuration Manager-managed clients.
Question 3: What device identity prerequisite must be met for co-management to work with Microsoft Intune?
- Devices must be Azure AD joined only with no on-premises AD connection
- Devices must be either Hybrid Azure AD joined or Azure AD joined (Correct answer)
- Devices must remain on-premises AD joined without any Azure AD registration
- Devices must have Windows 11 installed and be registered in Microsoft Endpoint Manager
Correct answer: Devices must be either Hybrid Azure AD joined or Azure AD joined
Co-managed devices must have an Azure AD identity, achieved through either Hybrid Azure AD Join (synced from on-premises AD) or direct Azure AD Join.
Question 4: What is the minimum Configuration Manager current branch version required to enable co-management?
- Configuration Manager version 1710 (Correct answer)
- Configuration Manager version 2012 R2
- Configuration Manager version 2002
- Configuration Manager version 1902
Correct answer: Configuration Manager version 1710
Co-management support was introduced in Configuration Manager current branch version 1710, making it the minimum supported version.
Question 5: Which of the following is NOT an available co-management workload that can be switched from Configuration Manager to Intune?
- Compliance policies
- Windows Update policies
- Hardware inventory collection (Correct answer)
- Resource access policies
Correct answer: Hardware inventory collection
Hardware inventory is not a co-management workload; it always remains with Configuration Manager and cannot be switched to Intune.
Question 6: In a co-management scenario where both Configuration Manager and Intune apply settings to the same area, what determines which settings take effect?
- Configuration Manager settings always take precedence over Intune
- Intune settings always override Configuration Manager settings
- The configured workload authority slider determines which platform's settings apply (Correct answer)
- Both sets of settings are merged and applied together on the device
Correct answer: The configured workload authority slider determines which platform's settings apply
The workload authority configured in the co-management settings (the slider for each workload) determines which management platform's policies are authoritative and applied to devices.
Question 7: What is a 'pilot collection' used for in co-management configuration?
- Testing Windows Autopilot deployment profiles on a subset of new devices
- Gradually moving specific devices to Intune workload management before a full organization-wide rollout (Correct answer)
- Collecting hardware inventory data from a representative sample of managed devices
- Piloting Windows feature updates to a controlled test group before broad deployment
Correct answer: Gradually moving specific devices to Intune workload management before a full organization-wide rollout
Pilot collections allow administrators to switch specific workloads to Intune only for a defined subset of devices, validating the change before applying it to all co-managed devices.
What is co-management in the context of Microsoft endpoint management?