MD-101 Co-management with Microsoft Endpoint Configuration Manager 2 — Questions and Answers
Question 1: How many distinct co-management workloads can be individually configured in Microsoft Endpoint Manager?
- 4 workloads
- 6 workloads
- 7 workloads (Correct answer)
- 10 workloads
Correct answer: 7 workloads
There are 7 co-management workloads: Compliance policies, Device Configuration, Endpoint Protection, Resource Access Policies, Office Click-to-Run apps, Windows Update policies, and Client apps.
Question 2: Which co-management workload, when switched to Intune, enables management of Microsoft Defender Antivirus and Windows Firewall policies from the Intune console?
- Device Configuration workload
- Compliance Policies workload
- Endpoint Protection workload (Correct answer)
- Resource Access Policies workload
Correct answer: Endpoint Protection workload
The Endpoint Protection workload, when set to Intune, transfers control of Microsoft Defender Antivirus, Windows Defender Firewall, and related security settings to Intune management.
Question 3: What must be configured in Azure AD to allow existing Configuration Manager clients to automatically enroll in Intune for co-management?
- An Azure AD device enrollment restriction policy targeting the devices
- Azure Services configuration with a dedicated Intune connector in Configuration Manager
- Cloud Management Gateway with Intune synchronization enabled
- Automatic MDM enrollment set to 'All' or 'Some' in Azure AD, or via Group Policy MDM enrollment settings (Correct answer)
Correct answer: Automatic MDM enrollment set to 'All' or 'Some' in Azure AD, or via Group Policy MDM enrollment settings
Automatic MDM enrollment must be enabled in Azure AD (set to All or Some users) or configured via Group Policy to trigger silent Intune enrollment for existing Configuration Manager clients.
Question 4: What is the primary purpose of the Cloud Management Gateway (CMG) in co-managed environments?
- It replaces the Intune connector and handles all device enrollment requests
- It enables Configuration Manager to manage and communicate with internet-based clients without requiring VPN (Correct answer)
- It synchronizes policy differences between Configuration Manager and Intune in real time
- It serves as a backup management channel automatically activated if Intune becomes unavailable
Correct answer: It enables Configuration Manager to manage and communicate with internet-based clients without requiring VPN
The Cloud Management Gateway (CMG) allows Configuration Manager to reach and manage clients over the internet, which is essential for co-managed devices that work remotely without VPN connectivity.
Question 5: Which Azure AD Connect feature is required to enable Hybrid Azure AD Join for co-management scenarios?
- Azure AD Connect with device writeback enabled (Correct answer)
- Azure AD Connect with password hash synchronization only, no additional features needed
- Azure AD Application Proxy configured for internal device registration
- Azure AD B2B collaboration settings enabled for device objects
Correct answer: Azure AD Connect with device writeback enabled
Hybrid Azure AD Join requires Azure AD Connect with device writeback enabled, which allows on-premises AD-joined devices to also be registered in Azure AD.
Question 6: When the 'Client Apps' workload is switched to Intune in a co-management configuration, what happens to applications already deployed through Configuration Manager?
- All Configuration Manager app deployments are immediately uninstalled and removed from devices
- Existing Configuration Manager app deployments continue unaffected, but new app deployments should use Intune (Correct answer)
- Apps remain installed but must be manually re-deployed through Intune to receive future updates
- All application management transfers instantly to Intune, including existing deployment records
Correct answer: Existing Configuration Manager app deployments continue unaffected, but new app deployments should use Intune
Switching the Client Apps workload to Intune does not disturb existing Configuration Manager deployments; those apps remain installed and managed, while new deployments should be created in Intune.
Question 7: Which co-management workload must be set to Intune to allow Wi-Fi profiles, VPN configurations, and certificate profiles to be managed through the Intune admin center?
- Device Configuration workload
- Compliance Policies workload
- Endpoint Protection workload
- Resource Access Policies workload (Correct answer)
Correct answer: Resource Access Policies workload
The Resource Access Policies workload covers Wi-Fi profiles, VPN profiles, and certificate profiles, enabling cloud-based management of how devices connect to and authenticate with corporate resources.
How many distinct co-management workloads can be individually configured in Microsoft Endpoint Manager?