MD-101 Managing Modern Desktops (MD-101) Microsoft 3 — Questions and Answers
Question 1: An administrator configures an Intune device configuration profile for Windows 10 but users report the settings are not applying. What is the first step to diagnose the issue?
- Recreate the profile from scratch
- Check the profile assignment and scope tags (Correct answer)
- Restart the Intune service
- Re-enroll all affected devices
Correct answer: Check the profile assignment and scope tags
Verifying that the profile is correctly assigned to the right groups and that scope tags are configured correctly is the first diagnostic step.
Question 2: A Windows 11 device needs to have its disk encrypted using BitLocker, with the recovery key stored in Azure AD. Which Intune profile type should be configured?
- Endpoint protection profile (Correct answer)
- Device restrictions profile
- Identity protection profile
- Security baseline profile
Correct answer: Endpoint protection profile
BitLocker settings, including recovery key backup to Azure AD, are configured under the Endpoint Protection profile in Intune.
Question 3: Which Windows Autopilot deployment mode allows a technician to pre-provision a device so the end user only needs to complete minimal setup steps?
- User-driven mode
- Self-deploying mode
- White glove (pre-provisioning) mode (Correct answer)
- Reset mode
Correct answer: White glove (pre-provisioning) mode
White glove (pre-provisioning) mode lets a technician complete device-level provisioning before delivering the device to the end user.
Question 4: An organization wants to prevent users from installing apps from outside the Microsoft Store on managed Windows 10 devices. Which Intune setting accomplishes this?
- Configure App Locker via script
- Enable SmartScreen
- Set 'Allow All Trusted Apps' to Block in device restrictions (Correct answer)
- Configure Windows Defender Application Control
Correct answer: Set 'Allow All Trusted Apps' to Block in device restrictions
Setting 'Allow All Trusted Apps' (sideloading) to Block in Intune device restrictions prevents installation of apps from outside the Microsoft Store.
Question 5: A user leaves the company. The administrator needs to remove corporate data from the user's personal device enrolled via BYOD without affecting personal data. Which Intune action should be used?
- Wipe
- Retire (Correct answer)
- Delete
- Fresh Start
Correct answer: Retire
The Retire action removes corporate apps and data managed by Intune from a personal device while leaving personal data intact.
Question 6: Which Update Ring setting in Intune controls how long a device user can postpone a Windows update restart notification?
- Active hours
- Deadline grace period
- Engaged restart snooze period (Correct answer)
- Update deferral period
Correct answer: Engaged restart snooze period
The engaged restart snooze period controls how many days a user can snooze (postpone) restart notifications after an update is ready.
Question 7: An administrator wants to deploy a Win32 application via Intune to specific devices. What file format must the app be packaged in before uploading to Intune?
- .exe
- .msi
- .intunewin (Correct answer)
- .appx
Correct answer: .intunewin
Win32 apps must be packaged using the Microsoft Win32 Content Prep Tool, which produces an .intunewin file for upload to Intune.
An administrator configures an Intune device configuration profile for Windows 10 but users report the settings are not applying.
What is the first step to diagnose the issue?