MD-101 Managing Modern Desktops (MD-101) v1.0 2 — Questions and Answers
Question 1: A company wants to prevent users from installing unapproved apps on Windows 11 devices enrolled in Intune. Which feature should you configure?
- Windows Defender Firewall
- AppLocker or WDAC policies (Correct answer)
- BitLocker encryption
- Windows Sandbox
Correct answer: AppLocker or WDAC policies
AppLocker or Windows Defender Application Control (WDAC) policies restrict which applications users can run on managed devices.
Question 2: You need to deploy a Win32 app to Intune-managed devices. What file format must you convert the installer to before uploading to Intune?
- .msi
- .intunewin (Correct answer)
- .appx
- .msix
Correct answer: .intunewin
Win32 apps must be packaged as .intunewin files using the Microsoft Win32 Content Prep Tool before uploading to Intune.
Question 3: Which Windows Autopilot deployment mode allows a technician to pre-configure a device before delivering it to an end user?
- User-driven mode
- Self-deploying mode
- White glove (pre-provisioning) mode (Correct answer)
- Hybrid Azure AD join mode
Correct answer: White glove (pre-provisioning) mode
White glove (pre-provisioning) mode lets IT or partners complete the device provisioning phase before the user receives the device.
Question 4: An administrator needs to ensure that Intune-enrolled iOS devices automatically install a required app. Which assignment type should be used?
- Available for enrolled devices
- Required (Correct answer)
- Uninstall
- Available with or without enrollment
Correct answer: Required
Setting the app assignment to 'Required' forces the app to install automatically on targeted enrolled devices.
Question 5: A user reports that their Azure AD-joined Windows 11 device is not receiving Intune policies. What is the FIRST step to diagnose this?
- Reinstall Windows
- Check the device compliance status in Intune portal (Correct answer)
- Reset the user's password
- Disable Windows Defender
Correct answer: Check the device compliance status in Intune portal
Checking the device compliance status in the Intune portal reveals sync issues, policy errors, and non-compliance reasons.
Question 6: You want to configure devices so that users must re-authenticate after 15 minutes of inactivity. Which Intune policy type should you use?
- Endpoint security – Account protection
- Device configuration – Device restrictions (Correct answer)
- App protection policy
- Compliance policy
Correct answer: Device configuration – Device restrictions
Device restrictions profiles in Intune device configuration include screen timeout and lock settings for Windows devices.
Question 7: Which tool can you use to analyze Windows Autopilot deployment failures and retrieve detailed event logs from a device?
- Windows Admin Center
- MDMDiagnosticsTool.exe (Correct answer)
- Sysprep /audit
- DISM /Get-Packages
Correct answer: MDMDiagnosticsTool.exe
MDMDiagnosticsTool.exe collects Autopilot and MDM enrollment logs to help diagnose deployment failures.
A company wants to prevent users from installing unapproved apps on Windows 11 devices enrolled in Intune.
Which feature should you configure?