MD-101 Managing Modern Desktops (MD-101) Microsoft 4 — Questions and Answers
Question 1: A company uses Microsoft Defender for Endpoint and wants to integrate it with Intune for device compliance. What must be configured in Intune first?
- A Defender ATP connector in Intune compliance settings (Correct answer)
- A Custom compliance policy script
- An Endpoint detection and response (EDR) configuration profile
- A Microsoft 365 Defender workspace
Correct answer: A Defender ATP connector in Intune compliance settings
The Microsoft Defender for Endpoint connector must be enabled in Intune's device compliance settings to receive device risk signals.
Question 2: Which feature allows an organization to enforce that Windows Hello for Business is set up before a user can complete the Autopilot enrollment process?
- Enrollment Status Page (ESP) (Correct answer)
- Conditional Access requiring MFA
- Identity Protection policy
- Windows Hello provisioning policy
Correct answer: Enrollment Status Page (ESP)
The Enrollment Status Page (ESP) can block device use until required apps and policies, including Windows Hello, are configured.
Question 3: An Intune administrator needs to deliver a PowerShell script to Windows 10 devices. What is the maximum script size supported by Intune PowerShell scripts?
- 512 KB (Correct answer)
- 200 KB
- 1 MB
- 64 KB
Correct answer: 512 KB
Intune supports PowerShell scripts up to 512 KB in size when deployed via the PowerShell scripts feature.
Question 4: A Windows 10 device enrolled in Intune fails to sync policies. The administrator runs 'dsregcmd /status' and sees AzureAdJoined: YES but MDMEnrolled: NO. What does this indicate?
- The device is enrolled in Intune but Azure AD join failed
- The device is Azure AD joined but not enrolled in Intune MDM (Correct answer)
- The device needs to be reset before re-enrollment
- The device is enrolled via a group policy, not Intune
Correct answer: The device is Azure AD joined but not enrolled in Intune MDM
MDMEnrolled: NO means the device has not been enrolled in MDM (Intune), even though it has successfully joined Azure AD.
Question 5: Which Microsoft tool is used to analyze Windows Update compatibility issues and deployment readiness before upgrading to a new Windows version?
- Windows Update for Business reports
- Desktop Analytics (now integrated into Endpoint analytics) (Correct answer)
- Microsoft Assessment and Planning Toolkit
- Upgrade Readiness in Log Analytics
Correct answer: Desktop Analytics (now integrated into Endpoint analytics)
Desktop Analytics (now integrated into Microsoft Endpoint analytics) assesses app and driver compatibility before Windows feature update deployments.
Question 6: An administrator wants to configure a kiosk device in Intune that runs only a single UWP app with no access to other functions. Which configuration should be used?
- Assigned Access (single-app kiosk) profile (Correct answer)
- App locker policy
- Multi-app kiosk profile with one app listed
- Device restrictions with blocked app list
Correct answer: Assigned Access (single-app kiosk) profile
Assigned Access configured as a single-app kiosk restricts the device to running only one specified UWP application.
Question 7: A company needs to ensure that Windows devices automatically enroll in Intune when they join Azure AD. Which Azure AD setting enables this automatic MDM enrollment?
- Enable Intune automatic enrollment in Azure AD device settings
- Configure MDM user scope in Azure AD Mobility (MDM and MAM) (Correct answer)
- Set automatic enrollment in Intune device enrollment restrictions
- Enable hybrid Azure AD join in Azure AD Connect
Correct answer: Configure MDM user scope in Azure AD Mobility (MDM and MAM)
The MDM user scope setting in Azure AD Mobility (MDM and MAM) controls which users' devices automatically enroll in Intune upon Azure AD join.
A company uses Microsoft Defender for Endpoint and wants to integrate it with Intune for device compliance.
What must be configured in Intune first?