MD-101 Managing Modern Desktops (MD-101) Microsoft 2 — Questions and Answers
Question 1: A company wants to deploy Windows 11 to new devices using Windows Autopilot. Which Azure AD join type allows devices to be managed by Intune without requiring a hybrid configuration?
- Hybrid Azure AD Join
- Azure AD Join (Correct answer)
- Workplace Join
- Domain Join
Correct answer: Azure AD Join
Azure AD Join (cloud-only) allows devices to be fully managed by Intune without requiring on-premises Active Directory connectivity.
Question 2: An administrator needs to ensure that only compliant devices can access corporate resources in Microsoft 365. Which Intune feature should be configured?
- Device enrollment policies
- Conditional Access policies (Correct answer)
- App protection policies
- Device configuration profiles
Correct answer: Conditional Access policies
Conditional Access policies in Azure AD enforce compliance requirements before allowing access to corporate resources.
Question 3: A user's Windows 10 device shows 'Not Compliant' in Intune due to missing BitLocker encryption. What happens to the device's access to Exchange Online by default?
- Access is permanently blocked
- Access continues unchanged until manually revoked
- Access is blocked if a Conditional Access policy requires compliance (Correct answer)
- Access is limited to read-only mode
Correct answer: Access is blocked if a Conditional Access policy requires compliance
Non-compliant devices are only blocked from resources when a Conditional Access policy requiring device compliance is configured.
Question 4: Which Windows Update for Business setting controls the maximum number of days a feature update can be deferred?
- 180 days
- 365 days (Correct answer)
- 90 days
- 60 days
Correct answer: 365 days
Windows Update for Business allows feature updates to be deferred for up to 365 days.
Question 5: An organization uses Microsoft Endpoint Configuration Manager (MECM) and wants to co-manage devices with Intune. Which workload can be moved to Intune while keeping others in MECM?
- All workloads must be moved simultaneously
- Individual workloads can be selectively shifted to Intune (Correct answer)
- Only compliance policies can be moved to Intune
- Only device configuration can be moved to Intune
Correct answer: Individual workloads can be selectively shifted to Intune
Co-management allows granular control, letting administrators move individual workloads (compliance, device config, etc.) to Intune independently.
Question 6: A help desk technician needs to remotely assist a user with a Windows 10 device enrolled in Intune without interrupting the user's session. Which feature should be used?
- Quick Assist
- Remote Control in MECM
- Intune Remote Help (Correct answer)
- Windows Remote Assistance
Correct answer: Intune Remote Help
Intune Remote Help provides a cloud-based remote assistance solution that integrates with role-based access control in Intune.
Question 7: Which PowerShell cmdlet is used to check if a device is enrolled in Windows Autopilot?
- Get-AutopilotDevice
- Get-WindowsAutopilotInfo (Correct answer)
- Get-IntuneDevice
- Get-MgDevice
Correct answer: Get-WindowsAutopilotInfo
Get-WindowsAutopilotInfo is the PowerShell script/cmdlet used to retrieve device hardware hashes and check Autopilot enrollment status.
A company wants to deploy Windows 11 to new devices using Windows Autopilot.
Which Azure AD join type allows devices to be managed by Intune without requiring a hybrid configuration?