MD-101 Managing Modern Desktops (MD-101) v1.0 3 — Questions and Answers
Question 1: A company requires that only compliant devices can access Exchange Online. Which Azure AD feature enforces this requirement?
- Azure AD Identity Protection
- Conditional Access policies (Correct answer)
- Privileged Identity Management
- Azure AD Connect
Correct answer: Conditional Access policies
Conditional Access policies in Azure AD can require device compliance as a condition before granting access to cloud resources.
Question 2: You need to wipe corporate data from a personal device enrolled via MAM without affecting personal data. Which action should you perform in Intune?
- Full wipe
- Fresh Start
- Selective wipe (retire) (Correct answer)
- Autopilot Reset
Correct answer: Selective wipe (retire)
Selective wipe (retire) removes only corporate data and app configurations, leaving personal data and apps untouched on BYOD devices.
Question 3: Which Windows Update for Business setting controls how many days a feature update is deferred on managed devices?
- Quality update deferral
- Feature update deferral (Correct answer)
- Pause updates duration
- Delivery Optimization download mode
Correct answer: Feature update deferral
The feature update deferral setting delays installation of new Windows feature updates by a specified number of days (up to 365).
Question 4: A user's Windows 10 device is Azure AD joined. They need to access an on-premises file share that uses Windows authentication. What is the BEST solution?
- Re-join the device to the local Active Directory domain
- Configure Hybrid Azure AD Join (Correct answer)
- Enable Windows Hello for Business
- Install the Azure AD Connect agent on the file server
Correct answer: Configure Hybrid Azure AD Join
Hybrid Azure AD Join registers the device with both on-premises AD and Azure AD, enabling seamless SSO to on-premises resources.
Question 5: Which Microsoft Endpoint Manager feature allows you to set a maximum OS version that a device must not exceed to remain compliant?
- Update rings
- Compliance policies (Correct answer)
- Configuration profiles
- Enrollment restrictions
Correct answer: Compliance policies
Intune compliance policies include OS version range settings that mark devices non-compliant if they exceed the maximum allowed version.
Question 6: You need to deploy a PowerShell script to all Windows 11 Intune-managed devices to configure a registry key. Which Intune feature should you use?
- Proactive remediations (Remediations) (Correct answer)
- App configuration policies
- Win32 app deployment
- Device configuration – Administrative templates
Correct answer: Proactive remediations (Remediations)
Proactive remediations (now called Remediations) in Intune allow you to run detection and remediation PowerShell scripts on managed Windows devices.
Question 7: A Windows Hello for Business deployment requires that users authenticate with a PIN or biometric instead of a password. Which infrastructure component is required for a cloud-only (Azure AD) deployment?
- Active Directory Certificate Services (AD CS)
- Azure AD Premium P1 license (Correct answer)
- On-premises domain controllers
- Microsoft Identity Manager
Correct answer: Azure AD Premium P1 license
An Azure AD Premium P1 license is required to enable Windows Hello for Business in a cloud-only (Azure AD joined) deployment.
A company requires that only compliant devices can access Exchange Online.
Which Azure AD feature enforces this requirement?